VMware Fusion, Workstation RCE flaws patched
CERT-FR advisory details two VMware Fusion and Workstation vulnerabilities allowing remote code execution, fixed in version 26H1u1.
CERT-FR issued an advisory covering two vulnerabilities (CVE-2026-59346 and CVE-2026-59347) affecting VMware Fusion and Workstation versions prior to 26H1u1. Both flaws could allow an attacker to achieve remote code execution on affected systems. The advisory references Broadcom's security bulletin (VMSA-2026 #38288, published September 3, 2026) for further technical detail and remediation guidance.
No indication of active exploitation is provided in this advisory. Organizations running affected VMware Fusion or Workstation versions should apply the vendor-supplied patches to reach version 26H1u1 or later as soon as feasible, per the referenced Broadcom bulletin.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1114
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free