CVE-2026-22716: VMware Workstation out-of-bounds write vulnerability
Published Feb 27, 2026
·Updated
Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes.
Affected Software
1 affected component
VMware Workstation<=25H1
Event History
Feb 27, 2026
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-22716?
CVE-2026-22716 is classified with a moderate severity level due to information disclosure risks.
2
How do I fix CVE-2026-22716?
To mitigate CVE-2026-22716, users should upgrade VMware Workstation and Fusion to versions beyond 25H1.
3
Who is affected by CVE-2026-22716?
Hosts running VMware Workstation or VMware Fusion versions up to and including 25H1 are vulnerable to CVE-2026-22716.
4
What type of vulnerability is CVE-2026-22716?
CVE-2026-22716 is categorized as an out-of-bounds read vulnerability.
5
What information can be disclosed due to CVE-2026-22716?
CVE-2026-22716 allows an actor with non-administrative privileges on a guest VM to gain limited information from the host machine.