VMSA-2026-0007: VMware Workstation & Fusion Hypervisor Escape & Buffer Overflow Vulnerabilities Analysis

Technical analysis of VMSA-2026-0007: guest-to-host virtual machine escape flaws (CVE-2026-59346, CVE-2026-59347) in VMware Workstation and Fusion.

VMSA-2026-0007: VMware Workstation & Fusion Hypervisor Escape & Buffer Overflow Vulnerabilities Analysis
📌
Security Roundup Series: Week of September 18, 2026 • 5 min read deep dive

Broadcom has issued security advisory VMSA-2026-0007 addressing integer overflow and heap buffer overflow vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) allowing guest-to-host virtual machine escape.

🚨
Vulnerability Intelligence: CVE ID: CVE-2026-59346 & CVE-2026-59347 (VMSA-2026-0007) (CWE-190 / CWE-122: Integer Overflow & Heap Buffer Overflow in Virtual Devices) Severity: Critical (CVSS 9.3) Status: 🚨 Virtual Machine Escape Advisory / Urgent Update Affected Systems: VMware Workstation 17.x, VMware Fusion 13.x

Hypervisor Memory Escape Mechanics

The flaws exist in the virtual USB and SVGA device emulation controllers. Malicious code running in a guest virtual machine can trigger an integer calculation error during buffer allocation, corrupting the host VMM process and executing arbitrary code on the underlying host operating system.


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther