CVE-2026-22716 Details
Description
Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes.
An out-of-bounds write vulnerability has been identified in VMware Workstation 25H1 and earlier versions, across all platforms. This vulnerability allows a user with non-administrative privileges on a guest virtual machine to cause certain VMware Workstation processes to terminate unexpectedly.
Users can upgrade to VMware Workstation 25H2u1 to address this vulnerability. This version is available through the VMware Workstation Pro 25H2 release notes on the Broadcom website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 27, 2026CISA-ADP
Assessed Feb 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36986 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| VMware Workstation | >= 17, <= 25H2 |
CPE
Remediation
| |
| VMware Fusion | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 27, 2026 | CVE Modified | [email protected] |
| Feb 27, 2026 | New CVE Received | [email protected] |
Volerion