FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Critical VM Escape Vulnerabilities in VMware Workstation and Fusion VMSA-2026-0007

VMSA-2026-0007 addresses critical vulnerabilities in VMware Workstation and Fusion that enable guest-to-host escapes. Attackers with administrative privileges on a guest VM can exploit memory corruption flaws—including heap overflows, Use-After-Free (UAF), and type confusion—within device emulation components such as the SVGA device and USB controllers. Successful exploitation allows arbitrary code execution (ACE) on the underlying host operating system with the privileges of the VMware process. This breaks the fundamental isolation premise of virtualization, facilitating full host compromise, data exfiltration, and lateral movement across the physical network. Immediate updates to patched versions are required to mitigate these high-CVSS risks.


LINK COPIED TO CLIPBOARD