Vercel Confirms KVM Zero-Day Behind Claimed Guest-to-Host Root Escape
Vercel has confirmed a KVM zero-day reported through its Sandbox bounty program after a researcher claimed a full guest-to-host escape. Technical details, affected versions and remediation guidance remain...
Linux KVM/arm64 Flaw Breaks VM Isolation and Exposes Host Memory
CVE-2026-89775 can leave stale writable mappings available to an ARM64 guest when KVM nested virtualization is enabled, creating a path to host-memory access and VM escape. Operators should...
Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server
A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control...
Januscape: 16-Year-Old Linux KVM Flaw (CVE-2026-53359) Lets Malicious VMs Corrupt Host Kernel Memory
A 16-year-old flaw in Linux KVM, tracked as CVE-2026-53359 and dubbed Januscape, lets a malicious guest VM corrupt host kernel memory via a use-after-free in the shadow MMU's...