Broadcom patched two VMware Workstation and Fusion flaws that let a local administrator inside a guest VM reach the host, fixing them in 26H1u1 for the 25H2 and 26H1 lines. One bug is tracked as CVE-2026-59346 and the other as CVE-2026-59347.
The first issue is an integer overflow in VMXNET3 virtual network handling; the second is a stack-based buffer overflow in the VMX process path. In both cases, a privileged guest can make VMware code on the host do the work, so the sandbox boundary fails and host-level code execution becomes possible.
For people running untrusted or semi-trusted VMs on Workstation or Fusion, the exposure sits with the machine running the VM, not just the guest OS. That means the host remains the blast radius until the patched build is in place, especially on developer workstations and test systems that share data or run multiple VMs.