> VM's shouldn't connect to the internet.
They're not (except to update them). They're just plain old VisualStudio dev machines with as much MS rubbish stripped out of them as possible - including anything to do with Office and anti virus scanning. They're normally installed as either a private network or NAT through the Mac. All 'internet' access is through the Mac's applications - browsers, mail, etc.
A lot of this client security stuff is FUD. Spectre and Meltdown aren't any real concern for a VM running on a private host -- I say aren't a real concern; the real concern is the loss of performance.
The main performance improvements are for graphics-intensive stuff which is never used in my Windos VMs (I don't play games, etc.)
There was a major performance improvement around version 5 but the last couple of updates have been quite minor.
Given that I've avoided updating to version 8/8.5 and 10 on one machine, I've saved a couple of hundred dollars. The other machines are running 8.5 for which I noticed absolutely no improvement in performance other than that from the Mac hardware upgrade.
As I said, I'm really struggling to see any reason to "upgrade" to 11, especially as the *free* Mojave update hasn't killed VMWare (feeding my suspicion that there's been few material updates).
Obviously it's my specific use case. I'm sure other people's mileage will vary.