As cited
Copy frozen at (site build).
vulnerabilities
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape (CVE-2026-64561) is a Linux kernel vulnerability in KVM/x86's shadow memory management unit that could permit an attacker with kernel privileges in a level 1 guest virtual machine to break out of KVM isolation and run code on the host system. The exposure exists when nested virtualization is enabled for untrusted guests.
Why it matters: Hypervisor administrators and cloud providers using KVM with nested virtualization and untrusted workloads face immediate risk of host compromise and lateral movement; patch or disable nested virtualization to eliminate the attack surface.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape (CVE-2026-64561) is a Linux kernel vulnerability in KVM/x86's shadow memory management unit that could permit an attacker with kernel privileges in a level 1 guest virtual machine to break out of KVM isolation and run code on the host system. The exposure exists when nested virtualization is enabled for untrusted guests.
Why it matters: Hypervisor administrators and cloud providers using KVM with nested virtualization and untrusted workloads face immediate risk of host compromise and lateral movement; patch or disable nested virtualization to eliminate the attack surface.
- Source published
- First seen by Cybersecurity Tracker