Broadcom Issues Critical Patches for VMware Workstation and Fusion Vulnerabilities
AI-generated from multiple sources. Verify before acting on this reporting.
SAN JOSE, Calif. — Broadcom announced on Thursday the release of security patches addressing two critical and high-severity vulnerabilities in its VMware Workstation and Fusion virtualization software. The updates, issued on Sept. 4, 2026, aim to neutralize integer overflow and stack-based buffer overflow flaws that could allow attackers to execute arbitrary code on host systems.
The vulnerabilities affect widely used desktop virtualization tools employed by developers, IT administrators, and enterprise users to run multiple operating systems simultaneously. Security researchers identified the defects as capable of compromising the integrity of the host machine if exploited successfully. Successful exploitation would grant an attacker the ability to run unauthorized commands with the privileges of the user running the virtual machine, potentially leading to full system compromise.
Broadcom stated that the flaws stem from specific memory handling errors within the software's architecture. The integer overflow bug occurs when the application processes data larger than the allocated variable size, while the stack-based buffer overflow arises when data exceeds the bounds of a fixed-size buffer on the call stack. Both conditions create an opening for malicious actors to inject and execute code.
The technology giant urged all users of VMware Workstation and Fusion to apply the available updates immediately. The patches are distributed through standard update channels for both Windows and macOS platforms. Broadcom emphasized that unpatched systems remain exposed to potential remote attacks, particularly in environments where virtual machines process untrusted data or connect to external networks.
The announcement comes as cybersecurity firms have increasingly highlighted risks within virtualization infrastructure, which serves as a foundational layer for cloud computing and software development. While the specific details of any active exploitation campaigns were not disclosed, the severity ratings assigned to the flaws indicate a significant risk profile requiring urgent remediation.
Industry analysts noted that the timing of the release underscores the ongoing challenges in securing complex virtualization environments. As organizations rely more heavily on containerized and virtualized workloads, the attack surface for potential intrusions continues to expand. The patches address the known code execution vectors, but questions remain regarding whether other related vulnerabilities exist within the broader VMware ecosystem or if similar flaws affect legacy versions of the software that are no longer supported.
Broadcom has not indicated if any organizations have confirmed incidents resulting from these specific bugs. The company advised users to verify their installation versions against the advisory list to ensure full protection. As the cybersecurity landscape evolves, continued vigilance and rapid patch deployment remain essential for maintaining the security of virtualized infrastructure.