CVE-2026-41702Patch(vmware / fusion)

HIGHCVSS 7.0 · HIGH

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch vmware fusion systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fusion

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 30 mentions across 8 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 20 signals
  • Disclosure: 9 classified signals
  • General: 4 classified signals
  • Peaked 7d ago at 8 mentions (2026-05-14); latest day: 1
  • 30 total mentions across 8 days

Affected systems

Vendors
Products
fusion

Deep dive

Activity timeline30 mentions / 8d
02468Mentions · 2026-05-14: 8Mentions · 2026-05-15: 7Mentions · 2026-05-17: 1Mentions · 2026-05-18: 4Mentions · 2026-05-19: 6Mentions · 2026-05-21: 1Mentions · 2026-05-22: 2Mentions · 2026-06-02: 1PoC Mentioned / Linked · 2026-05-17: 1PoC Mentioned / Linked · 2026-05-19: 2Exploit Tool / Code · 2026-05-17: 1Active Exploitation · 2026-05-19: 1Patch / Workaround · 2026-05-14: 8Patch / Workaround · 2026-05-15: 3Patch / Workaround · 2026-05-18: 2Patch / Workaround · 2026-05-22: 1Technical Details · 2026-05-14: 7Technical Details · 2026-05-15: 6Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-19: 2Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 105-1405-1505-1705-1805-1905-2105-2206-02
Signal classification5 categories
Patch
1446.7%
Disclosure
930.0%
General
413.3%
PoC
26.7%
Active Exploitation
13.3%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-05-148
Patch8
2026-05-157
Disclosure3General1Patch3
2026-05-171
PoC1
2026-05-184
Disclosure2Patch2
2026-05-196
Active Exploitation1Disclosure3General1PoC1
2026-05-211
General1
2026-05-222
Disclosure1Patch1
2026-06-021
General1
Full discourse20 posts
  • Coiffeur@Coiffeur0x90
    PoC

    🏴‍☠️ I can finally share a VMware 0day I discovered that led to CVE-2026-41702 (LPE as root). Funny enough, I found the bug in my hotel room after the second day of attending Csaba Fitzl (@theevilbit) & Gergely Kalman (@gergely_kalman) training at Zer0con. https://therealcoiffeur.com/c111000.html https://t.co/qSjzSKNXDi

    Post summary

    The author has discovered a local privilege escalation bug in VMware (CVE-2026-41702), shares a PoC via a link, but does not report active exploitation or provide a patch.

    10123472628951.1K
    573 followersView on X
  • 蓝点网@landiantech
    Patch

    #下载 博通发布 VMware #Fusion Pro 26H1,这是适用于 macOS 系统的免费虚拟机软件 (现在也已经完全免费)。 本次更新博通为用户带来虚拟机备注、虚拟机创建和开机时间等方便用户区分虚拟机,同时修复安全漏洞 CVE-2026-41702,本次更新还支持更多 Linux 发行版。 下载地址:https://ourl.co/112982?x https://t.co/AGWri5XlUF

    Post summary

    The tweet announces VMware Fusion Pro 26H1, highlighting that the update includes a patch for CVE‑2026‑41702 and adds new features for macOS users.

    5120907615.1K
    36.9K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    VMware Fusion CVE-2026-41702 allows local users to gain root access via a TOCTOU race condition. Secure your host and update to 26H1 immediately! #VMware #CyberSecurity #InfoSec #RootAccess #Vulnerability #CVE #VMwareFusion #SysAdmin #TechNews #Broadcom https://securityonline.info/vmware-fusion-privilege-escalation-cve-2026-41702-toctou/ https://t.co/Zh00JEtscb

    Post summary

    CVE-2026-41702 is a local privilege escalation in VMware Fusion caused by a TOCTOU race condition, and users are advised to update to version 26H1 to mitigate the vulnerability.

    110110943
    12.5K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary.』 VMSA-2026-0003: VMware Fusion updates address privilege escalation vulnerability (CVE-2026-41702) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37454

    Post summary

    VMware Fusion has a TOCTOU privilege‑escalation flaw (CVE‑2026‑41702). VMware has released an update to remediate it, so users should install the patch.

    10002902
    6.9K followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🔓A VMware Fusion flaw (CVE-2026-41702) could let attackers with local access gain full root privileges on macOS systems. Broadcom patched the bug in Fusion 26H1, and no workaround is available. Update ASAP. Read more: https://thecyberedition.com/vmware-fusion-root-access-flaw/ #VMware #CyberSecurity

    Post summary

    The post alerts that VMware Fusion CVE‑2026‑41702 allows local privilege escalation to root, and the issue has been patched by Broadcom in Fusion 26H1, urging users to update immediately.

    0002091
    739 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Broadcom patched VMware Fusion for CVE-2026-41702, a high-severity TOCTOU flaw in a SETUID binary that could let a local user gain root privileges. Reported by Mathieu Farrell. #VMwareFusion #Broadcom #Pwn2Own https://ift.tt/ZvwyTaR

    Post summary

    Broadcom released a patch for VMware Fusion CVE-2026-41702, a TOCTOU vulnerability that could let local users attain root privileges.

    00011225
    4.3K followersView on X
  • iototsecnews@iototsecnews
    Patch

    VMware Fusion の脆弱性 CVE-2026-41702 が FIX:root 権限奪取の恐れ https://iototsecnews.jp/2026/05/15/vmware-fusion-flaw-could-allow-attackers-to-gain-root-privileges/ VMware Fusion の脆弱性 CVE-2026-41702 は、プログラムが安全性を確認するタイミングの隙を突かれてしまう “Time-of-Check Time-of-Use” という仕組みの不具合に起因します。それにより、システムが条件を確認してから、実際に処理を行うまでのわずかな間に、対象ファイルやリソースが密かに差し替えられる可能性があります。結果として、本来は許可されない root 権限が、攻撃者に奪われる恐れがあります。ご利用のチームは、ご注意ください。 #CVE202641702 #Fusion #VMware #Vulnerability

    Post summary

    VMware Fusion CVE‑2026‑41702 is a Time‑of‑Check/Use flaw that could allow root privilege escalation, but the issue has been fixed and no active exploitation is reported.

    00010119
    491 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:57 UTC: First exploit attempt in the wild. 0day Intel: 🏴‍☠️ I can finally share a VMware 0day I discovered that led to CVE-2026-41702

    Post summary

    The post announces that CVE-2026‑41702 has reportedly been targeted in a live exploit attempt, but offers no PoC, exploit code, patch info, or technical details.

    1000066
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    22:08 UTC: GPT-5 enrichment complete. 79 words. 1 citations. 0day Intel: 🏴‍☠️ I can finally share a VMware 0day I discovered that led to CVE-2026-41702

    Post summary

    The post merely claims a VMware 0day discovered next to CVE-2026-41702, offering no technical or actionable details.

    1000042
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    22:11 UTC: Thread live on @lyrie_ai. 0day Intel: 🏴‍☠️ I can finally share a VMware 0day I discovered that led to CVE-2026-41702

    Post summary

    The tweet announces discovery of a VMware 0day corresponding to CVE‑2026‑41702, but no PoC, exploit code, active use, patch, or technical details are provided.

    1000039
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    22:00 UTC: Lyrie Sentinel flagged it. 0day Intel: 🏴‍☠️ I can finally share a VMware 0day I discovered that led to CVE-2026-41702

    Post summary

    The statement announces the discovery of a VMware 0day (CVE-2026-41702) and indicates an intention to share a proof-of-concept.

    1000041
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    21:57 UTC: CVE-2026-41702 disclosed. 🏴‍☠️ I can finally share a VMware 0day I discovered that led to CVE-2026-41702 (LPE as root). Funny enough, I found the

    Post summary

    The post announces the discovery of a VMware zero‑day that leads to CVE‑2026‑41702, providing a local privilege escalation to root.

    1000046
    226 followersView on X
  • TodayInCyber@TodayInCyberIO
    Disclosure

    3/5 SAP S/4HANA and SAP Commerce Cloud (CVE-2026-34260, CVE-2026-34263): critical SQL injection and authentication bypass. VMware Fusion (CVE-2026-41702): high-severity privilege escalation.

    Post summary

    The text announces new critical vulnerabilities for SAP S/4HANA, SAP Commerce Cloud, and VMware Fusion, detailing SQL injection, authentication bypass, and privilege escalation risks.

    100009
    8 followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    Broadcom releases VMware Fusion security update for root access bug: Broadcom patched a high-severity VMware Fusion flaw, CVE-2026-41702, that could let local attackers gain root privileges. Broadcom released a security update for VMware Fusion to… https://securityaffairs.com/192136/security/broadcom-releases-vmware-fusion-security-update-for-root-access-bug.html?utm_source=dlvr.it&utm_medium=twitter https://t.co/ib1mqsvLyD

    Post summary

    Broadcom has issued a security update for VMware Fusion to address CVE-2026-41702, a high‑severity local privilege escalation flaw that could allow attackers to gain root access. The update mitigates the vulnerability with no evidence of active exploitation.

    0000151
    2.3K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-41702: VMware Fusion Privilege Escalation Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04jMW8Y0

    Post summary

    The brief excerpt announces a VMware Fusion privilege‑escalation vulnerability (CVE‑2026‑41702) and points to an article on its business impact and response, without detailed technical or exploit information.

    0000034
    32 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos VMware ❗ CVE-2026-41702 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-vmware-3/ https://t.co/ByrzctQPGc

    Post summary

    A tweet announces a VMware product vulnerability (CVE-2026-41702) and links to external sites for more information, but no PoC, exploit code, active exploitation, patch, or technical details are provided.

    0000099
    6.7K followersView on X
  • しーにゃ♪@公式@Syynya
    General

    VMware Fusionで権限昇格が可能な脆弱性 CVE-2026-41702 https://rocket-boys.co.jp/security-measures-lab/vmware-fusion-cve-2026-41702-privilege-escalation/ 『今回のCVE-2026-41702では、ローカルの非管理者ユーザーがroot権限へ昇格できる可能性が示されています。NVDでも、ローカル攻撃、低権限、ユーザー操作不要という条件が示されています』

    Post summary

    The post reports that CVE-2026-41702 allows local privilege escalation in VMware Fusion from non‑admin users to root, as documented by NVD, but provides no proof of exploitation, code, patch, or evidence of active attacks.

    00000104
    913 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    VMware Fusionで権限昇格が可能な脆弱性 CVE-2026-41702 https://rocket-boys.co.jp/security-measures-lab/vmware-fusion-cve-2026-41702-privilege-escalation/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces the discovery of a privilege‑escalation vulnerability (CVE‑2026‑41702) in VMware Fusion, with technical details posted on a security lab website.

    00000123
    407 followersView on X
  • Exploit Intel@exploit_intel
    Patch

    And while I've got your attention, patch your VMWare Fusion - CVE-2026-41702. https://exploit-intel.com/blog/posts/cve-2026-41702-vmware-fusion-cnxtmp-symlink-race/

    Post summary

    The tweet urges users to patch VMWare Fusion for CVE-2026-41702, with a link to a blog post for more information.

    00000137
    22 followersView on X
  • キタきつね@foxbook
    Disclosure

    ルートアクセス競争:TOCTOUの脆弱性(CVE-2026-41702)がVMware Fusionに影響 Root Access Race: TOCTOU Vulnerability (CVE-2026-41702) Hits VMware Fusion #DailyCyberSecurity (May 15) https://securityonline.info/vmware-fusion-privilege-escalation-cve-2026-41702-toctou/

    Post summary

    A new TOCTOU-based privilege‑escalation vulnerability (CVE‑2026‑41702) affecting VMware Fusion has been disclosed, with details on the race condition but no PoC, exploit code, or patch information provided.

    00000309
    4.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarefusion---

Explore more