cbcvebase.
CVE-2026-41702
published 2026-05-15

CVE-2026-41702: VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with…

PriorityP335high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.12%
2.3th percentile
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.

Affected

2 ranges
VendorProductVersion rangeFixed in
vmwarefusion< 26h126h1
vmwarefusion>= 2025H2 < 2026H12026H1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.