# VMware Fusion, Workstation RCE flaws patched

Published: 2026-09-04 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/5b362ec9-e769-519d-85ea-9fb8d4e430b9/vmware-fusion-workstation-rce-flaws-patched

> CERT-FR advisory details two VMware Fusion and Workstation vulnerabilities allowing remote code execution, fixed in version 26H1u1.

CERT-FR issued an advisory covering two vulnerabilities (CVE-2026-59346 and CVE-2026-59347) affecting VMware Fusion and Workstation versions prior to 26H1u1. Both flaws could allow an attacker to achieve remote code execution on affected systems. The advisory references Broadcom's security bulletin (VMSA-2026 #38288, published September 3, 2026) for further technical detail and remediation guidance.

No indication of active exploitation is provided in this advisory. Organizations running affected VMware Fusion or Workstation versions should apply the vendor-supplied patches to reach version 26H1u1 or later as soon as feasible, per the referenced Broadcom bulletin.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59346, CVE-2026-59347

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1114

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5b362ec9-e769-519d-85ea-9fb8d4e430b9/vmware-fusion-workstation-rce-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
