Fusion
Vendor:
First CVE: Jun 2, 2008 · Active for 18 years
131
Total CVEs
More Total CVEs than 99% of tracked products
6.9
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
1.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Fusion over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2008
18 years ago
Most Recent CVE
May 15, 2026
70 days ago
CVE Severity & Scoring
Fusion131 CVEs
43%
51%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local68 (51.9%)
Network24 (18.3%)
Unknown36 (27.5%)
Physical2 (1.5%)
Adjacent Network1 (0.8%)
Attack Complexity
Low75 (57.3%)
High20 (15.3%)
Unknown36 (27.5%)
User Interaction
None92 (70.2%)
Unknown36 (27.5%)
Required3 (2.3%)
Privileges Required
Low67 (51.1%)
High21 (16.0%)
None7 (5.3%)
Unknown36 (27.5%)
Top CVEs
Signals from CVEs in this product scope (131 CVEs).
131 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5753MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side | Jan 4, 2018 | 5.6 | 83 | NO | YES |
CVE-2020-3950HIGH VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalat | Mar 17, 2020 | 7.8 | 82 | YES | YES |
CVE-2025-22226MEDIUM VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a vir | Mar 4, 2025 | 6.0 | 62 | YES | NO |
CVE-2016-5330HIGH Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMw | Aug 8, 2016 | 7.8 | 55 | NO | YES |
CVE-2017-4901CRITICAL The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may all | Jun 8, 2017 | 9.9 | 54 | NO | YES |
CVE-2010-4297HIGH The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1 | Dec 6, 2010 | 7.2 | 36 | NO | YES |
CVE-2013-1406HIGH The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 | Feb 11, 2013 | 7.2 | 35 | NO | YES |
CVE-2026-41702HIGH VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrat | May 15, 2026 | 7.0 | 33 | NO | NO |
CVE-2009-2267MEDIUM VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build | Nov 2, 2009 | 6.9 | 32 | NO | YES |
CVE-2019-5521CRITICAL VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before 11.0.3 and 10.x befo | Sep 20, 2019 | 9.6 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (131 CVEs).
CISA KEV
2 CVEs
1.5% of CVEs· 96th percentile
Metasploit
2 CVEs
1.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
8.4% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (131 CVEs).
Media Mentions
Signals from CVEs in this product scope (131 CVEs).
Top CNAs Publishing CVEs For Fusion
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.5.9 | 1 | 5.5 | 0.4% | 0 | 0 |
| 8.5.8 | 4 | 6.5 | 0.7% | 0 | 0 |
| 8.5.7 | 4 | 6.5 | 0.7% | 0 | 0 |
| 8.5.6 | 4 | 6.5 | 0.7% | 0 | 0 |
| 8.5.5 | 4 | 6.5 | 0.7% | 0 | 0 |
| 8.5.4 | 5 | 7.2 | 4.6% | 0 | 1 |
| 8.5.3 | 5 | 7.2 | 4.6% | 0 | 1 |
| 8.5.2 | 5 | 7.2 | 4.6% | 0 | 1 |
| 8.5.10 | 1 | 5.5 | 0.4% | 0 | 0 |
| 8.5.1 | 6 | 7.5 | 3.9% | 0 | 1 |
| 8.5.0 | 4 | 8.5 | 5.3% | 0 | 1 |
| 8.5 | 2 | 5.4 | 1.0% | 0 | 0 |
| 8.1.1 | 7 | 7.2 | 3.4% | 0 | 1 |
| 8.1.0 | 5 | 7.9 | 4.3% | 0 | 1 |
| 8.1 | 2 | 5.4 | 1.0% | 0 | 0 |
| 8.0.2 | 7 | 7.2 | 3.4% | 0 | 1 |
| 8.0.1 | 7 | 7.2 | 3.4% | 0 | 1 |
| 8.0.0 | 5 | 7.9 | 4.3% | 0 | 1 |
| 8.0 | 2 | 5.4 | 1.0% | 0 | 0 |
| 7.1.1 | 2 | 7.0 | 1.7% | 0 | 0 |