daily cyber × ai intelligence

index

tagged

[CVE-2026-59346]

1 edition · 1 item

September 7, 2026

  • VMware Workstation and Fusion got fixes for a VMXNET3 integer overflow (CVE-2026-59346, CVSS 9.3) that lets a local administrator inside a guest execute code on the host, plus an HGFS stack overflow (CVE-2026-59347, 8.1) giving execution as the VMX process. Both need local admin in the VM, there are no workarounds, and Broadcom reports no evidence of exploitation — worth noting against last month's vCenter activity, where exploitation of CVE-2026-59310 reached 361 unique victim IPs across 47 countries (The Hacker News, SecurityWeek). Fixed in 26H1u1. · Exploitation & Active Attacks

in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart