CVE-2026-41702
EUVD-2026-3051015.05.2026, 07:16
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| vmware | fusion | 2025H2 ≤ 𝑥 < 2026H1 | CNA |
Vulnerability Media Exposure