CVE-2026-22716Patch

LOWCVSS 5.0 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-26); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Patch / Workaround · 2026-02-26: 2Technical Details · 2026-02-27: 202-2602-27
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-262
Patch2
2026-02-272
Disclosure2
Full discourse4 posts
  • ((yuki)|(kwmt)|(kawaman))@yuki_kawamitsu
    Patch

    Workstation や Fusion のマイナーナンバリングどうするんだ?と、心配してたけど 25H2u1 にするのか... 🤔 VMSA-2026-0002: VMware Workstation and Fusion updates address multiple vulnerabilities (CVE-2026-22715, CVE-2026-22716, CVE-2026-22717, CVE-2026-22722) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36986

    Post summary

    The post references VMware’s VMSA‑2026‑0002 advisory, noting that updates for Workstation and Fusion address several CVEs, indicating a patch is available.

    00050352
    1.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22716 Out-of-Bound Read Vulnerability in VMware Workstation 25H1 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22716

    Post summary

    A new out‑of‑bounds read vulnerability (CVE‑2026‑22716) affecting VMware Workstation 25H1 and earlier has been disclosed, with limited technical details and no evidence of exploitation, patch, or PoC.

    0000046
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22716 Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limite… https://www.cve.org/CVERecord?id=CVE-2026-22716

    Post summary

    A new out‑of‑bound read vulnerability (CVE‑2026‑22716) in VMware Workstation 25H1 and earlier allows non‑administrator guest users to read memory, with no PoC, exploit, patch, or active exploitation reported.

    0000083
    56.6K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    VMSA-2026-0002: VMware Workstation and Fusion updates address multiple vulnerabilities (CVE-2026-22715, CVE-2026-22716, CVE-2026-22717, CVE-2026-22722) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36986

    Post summary

    VMware released updates for Workstation and Fusion that address several CVEs, with a link to the official advisory.

    00000362
    6.7K followersView on X

Explore more