← Vulnerability feed

Vulnerability record · CVE-2026-41702 · published 15 May 2026

CVE-2026-41702: Vmware fusion toctou race condition vulnerability

Vmware · Fusion

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.

7.0 CVSS 3.1 High EPSS 0.11% · top 99.0% CWE-367 · TOCTOU race condition
7.0CVSS 3.1 base score
0.11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-41702 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-3950VMware Fusion, VMRC and Horizon Client setuid privilege escalationVMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac mishandle setuid binaries, allowing a local user to gain root. The flaw affec…KEVEPSS 7.3%analysed6.0CVE-2025-22226VMware ESXi, Workstation and Fusion HGFS out-of-bounds read leaks vmx memoryVMware ESXi, Workstation, Fusion and related cloud products contain an out-of-bounds read in the HGFS (Host Guest File System) component. A malicious…KEVEPSS 1.8%analysed9.9CVE-2017-4901Vmware fusion memory buffer overflow vulnerabilityThe drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acc…EPSS 20%9.6CVE-2019-5521Vmware fusion out-of-bounds read vulnerabilityVMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (1…EPSS 1.6%9.3CVE-2012-3288Vmware workstation improper input validation vulnerabilityVMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware…EPSS 3.8%9.3CVE-2011-3868Vmware workstation memory buffer overflow vulnerabilityBuffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remot…EPSS 5.8%9.1CVE-2019-5541Vmware workstation out-of-bounds write vulnerabilityVMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network ad…EPSS 1.4%9.0CVE-2012-2449Vmware workstation memory buffer overflow vulnerabilityVMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2026-41702), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.