VM Product Security Update Advisory (CVE-2026-41702)
- Security updates have been released to address vulnerabilities in VM products.
- the target product is VM Fusion, with versions 25H2 and 26H1 mentioned.
- the vulnerability addressed is CVE-2026-41702, a Time Of Check To Time Of Use (TOCTOU) local privilege escalation vulnerability in VM Fusion.
- the vulnerability has been patched in the latest update.
- VM has advised customers to update to the latest version of the Vulnerability Patch by following the instructions on the reference site.