Proof of concept exploit released for critical VMware VMXNET3 security flaw
Security researchers have detailed a guest-to-host code execution vulnerability in VMware Workstation and Fusion, following the release of a public proof-of-concept exploit.
FTMQ Security, written by our newsroom0 views
Howl.link reported on October 8 that details and a public proof-of-concept exploit have been released for a security flaw in VMware Workstation and Fusion. The vulnerability, tracked as CVE-2026-59346, affects the VMXNET3 virtual network adapter. [1]
According to reports from Cyber Press and SQ Magazine, the critical flaw enables guest-to-host execution and virtual machine escapes. Cyber Press noted that the release of the proof-of-concept exploit allows code execution from a guest virtual machine on the host system. [7][8]
Related security disclosures have also emerged for other software platforms. CyberSecurityNews reported that hackers are actively exploiting a critical Citrix NetScaler flaw to steal configuration data and deploy web shells. Separately, The Hacker News reported that attackers attempted to exploit an arbitrary file access flaw in Atlassian Data Center products, tracked as CVE-2026-21589 with a CVSS score of 9.3, within two hours of public disclosure. [5][6]
Additional proof-of-concept exploits were published for other applications this week. GBHackers News reported on unpatched remote code execution flaws in LMCache and Zammad, while CyberSecurityNews noted a separate proof-of-concept release for a critical Atlassian flaw that can grant administrative access to Jira. [2][3][4]
In short
- A public proof-of-concept exploit has been detailed for VMware flaw CVE-2026-59346 in the VMXNET3 driver.
- The VMware flaw allows guest-to-host code execution and virtual machine escapes.
- Atlassian Data Center products faced exploitation attempts within two hours of details being released for CVE-2026-21589.
- Hackers are actively exploiting a Citrix NetScaler flaw to deploy web shells and steal configuration files.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]VMware Workstation and Fusion VMXNET3 Flaw CVE-2026-59346 Detailed With Public PoC ExploitHowl.link, 21h ago (the report this story comes from)
- [2]Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit AvailableGBHackers News, 12h ago
- [3]PoC Exploit Released for Critical Atlassian Flaw That Can Lead to Jira Admin AccessCyberSecurityNews, 1d ago
- [4]PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code ExecutionGBHackers News, 11h ago
- [5]Hackers Exploit Critical Citrix NetScaler Flaw to Deploy Web Shells and Steal Configuration DataCyberSecurityNews, 12h ago
- [6]Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public DetailsThe Hacker News, 1d ago
- [7]VMware Security Alert: Critical VM Escape Flaw ExposedSQ Magazine, 10h ago
- [8]PoC Exploit Released for Critical VMware Flaw That Could Enable Guest-to-Host Code ExecutionCyber Press, 17h ago
Our newsroom writes these reports with the help of software, from the 8 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- Hackers target Rejetto HFS servers following critical session forgery vulnerability discoveryTop Stories, 3d ago
- Attackers begin exploiting critical Atlassian file access vulnerabilityThreat Intelligence, 1d ago
More in Bugs and Patches
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.