Multiple security vulnerabilities affecting VMware VMXNET3 versions The VMware VMXNET3 vulnerability affects these products: have been identified in VMware VMXNET3, a paravirtualized network adapter, which is the default NIC for modern guests. The flaws allow a privileged guest user to run code on the host, breaking the core promise of virtualization, which is isolation between a guest and its host. Affected versions include VMware Workstation 25H2 and 26H1, and VMware Fusion 25H2 and 26H1 (on macOS). The collective risk presented by these vulnerabilities requires prompt attention from administrators.
CVE-2026-59346 (CVSS 9.3 — Critical): A privileged guest user can exploit an integer-overflow flaw in the host's handling of TCP Segmentation Offload (TSO) packets to execute code on the host. The vulnerability survived a previous patch and was not addressed by bounds checks added for CVE-2025-41236.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting VMware VMXNET3 versions The VMware VMXNET3 vulnerability affects these products: have been identified in VMware VMXNET3, a paravirtualized network adapter, which is the default NIC for modern guests. The flaws allow a privileged guest user to run code on the host, breaking the core promise of virtualization, which is isolation between a guest and its host. Affected versions include VMware Workstation 25H2 and 26H1, and VMware Fusion 25H2 and 26H1 (on macOS). The collective risk presented by these vulnerabilities requires prompt attention from administrators.
CVE-2026-59346 (CVSS 9.3 — Critical): A privileged guest user can exploit an integer-overflow flaw in the host's handling of TCP Segmentation Offload (TSO) packets to execute code on the host. The vulnerability survived a previous patch and was not addressed by bounds checks added for CVE-2025-41236.[emaillocker id="1283"]
CVE-2025-41236: This vulnerability is not described in detail, but it is mentioned as an earlier issue that did not address the root cause of the VMXNET3 flaw.
We recommend you to update VMware Workstation to version 26H1u1 or later.
The following reports contain further technical details:
[/emaillocker]