CVE-2026-22715: VMware Workstation/Fusion NAT vulnerability
VMWare Workstation and Fusion contain a logic flaw in the management of network packets.
Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's.
Resolution: To remediate CVE-2026-22715 please upgrade to VMware Workstation or Fusion Version 25H2U1
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22715?
CVE-2026-22715 is classified with a high severity level due to its potential to allow network interruptions or interceptions between Guest VMs.
How do I fix CVE-2026-22715?
To remediate CVE-2026-22715, ensure that you update VMware Workstation or Fusion to the latest version that addresses this vulnerability.
What impact could CVE-2026-22715 have on my system?
CVE-2026-22715 could allow an attacker with administrative privileges on one Guest VM to disrupt or intercept network traffic of other Guest VMs.
Who is affected by CVE-2026-22715?
CVE-2026-22715 affects users of VMware Workstation and VMware Fusion versions up to 25H2U1 who utilize Guest VMs.
What are the known attack vectors for CVE-2026-22715?
The known attack vector for CVE-2026-22715 involves a malicious actor with administrative privileges on a Guest VM exploiting the logic flaw to manipulate network connections.