{"id":14754,"date":"2026-05-14T09:22:24","date_gmt":"2026-05-14T09:22:24","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=14754"},"modified":"2026-05-14T09:22:24","modified_gmt":"2026-05-14T09:22:24","slug":"excessive-severity-vulnerability-patched-in-vmware-fusion","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=14754","title":{"rendered":"Excessive-Severity Vulnerability Patched in VMware Fusion"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><strong>Broadcom introduced on Thursday that it has launched a VMware Fusion replace to patch a high-severity vulnerability.\u00a0<\/strong><\/p>\n<p>The flaw, tracked as CVE-2026-41702 and rated \u2018vital\u2019 by the seller, was reported by Mathieu Farrell.<\/p>\n<p>An <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37454?utm_campaign=VCF_FY26_VCF_VMSA-2026-0003_MKT_CM_5831&amp;utm_content=VCF_FY26_VCF_VMSA-2026-0003_5831_SecurityAlert_MKT_TRANS_EM_11081\" target=\"_blank\" rel=\"noreferrer noopener\">advisory<\/a> describes CVE-2026-41702 as a time-of-check time-of-use (TOCTOU) flaw that \u201chappens throughout an operation carried out by a SETUID binary\u201d.\u00a0<\/p>\n<p>\u201cA malicious actor with native non-administrative person privileges might exploit this vulnerability to escalate privileges to root on the system the place Fusion is put in,\u201d the advisory explains.\u00a0<\/p>\n<p>VMware might announce a number of extra patches within the coming days, as its merchandise might be focused at this week\u2019s Pwn2Own hacking competitors. VMware proprietor Broadcom has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogs.vmware.com\/security\/2026\/05\/vmware-at-pwn2own-berlin-2026.html\">despatched members of its safety workforce<\/a> to the occasion, the place contributors are anticipated to exhibit ESX exploits that may earn them as much as $200,000.<\/p>\n<p>VMware Workstation, which in recent times has earned <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/vmware-flaws-that-earned-hackers-340000-at-pwn2own-patched\/\">vital rewards<\/a> for Pwn2Own contributors, has been faraway from the record of targets.\u00a0<\/p>\n<div class=\"zox-post-ad-wrap\"><span class=\"zox-ad-label\">Commercial. Scroll to proceed studying.<\/span><\/div>\n<p>Broadcom\u2019s advisory doesn&#8217;t point out CVE-2026-41702 being utilized in assaults, however vulnerabilities in VMware merchandise are sometimes <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/vmware-aria-operations-vulnerability-exploited-in-the-wild\/\">exploited within the wild<\/a>. CISA\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?f%5B0%5D=vendor_project%3A851\">KEV catalog<\/a> presently contains 26 VMware flaws.\u00a0<\/p>\n<p><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/vmware-aria-operations-vulnerability-could-allow-remote-code-execution\/\">VMware Aria Operations Vulnerability Might Permit Distant Code Execution<\/a><\/p>\n<p><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/2024-vmware-flaw-now-in-attackers-crosshairs\/\">2024 VMware Flaw Now in Attackers\u2019 Crosshairs<\/a><\/p>\n<p><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/exploit-for-vmware-zero-day-flaws-likely-built-a-year-before-public-disclosure\/\">Exploit for VMware Zero-Day Flaws Possible Constructed a 12 months Earlier than Public Disclosure<\/a>\n\t\t\t<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Broadcom introduced on Thursday that it has launched a VMware Fusion replace to patch a high-severity vulnerability.\u00a0 The flaw, tracked as CVE-2026-41702 and rated \u2018vital\u2019 by the seller, was reported by Mathieu Farrell. An advisory describes CVE-2026-41702 as a time-of-check time-of-use (TOCTOU) flaw that \u201chappens throughout an operation carried out by a SETUID binary\u201d.\u00a0 \u201cA [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":14756,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[4283,7623,2800,2498,1061],"class_list":["post-14754","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-fusion","tag-highseverity","tag-patched","tag-vmware","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/14754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14754"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/14754\/revisions"}],"predecessor-version":[{"id":14755,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/14754\/revisions\/14755"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/14756"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-15 10:43:43 UTC -->