Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Home/CyberSecurity News/Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
CyberSecurity News

Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape

Key Takeaways A critical vulnerability, CVE-2026-64561 (Zapscape), has been identified in the Linux kernel’s KVM virtualization component. This flaw allows a malicious guest virtual machine to...

Sarah simpson
Sarah simpson
August 7, 2026 3 Min Read
4 0

Key Takeaways

  • A critical vulnerability, CVE-2026-64561 (Zapscape), has been identified in the Linux kernel’s KVM virtualization component.
  • This flaw allows a malicious guest virtual machine to escape its isolated environment and gain root access to the underlying Linux host.
  • The vulnerability specifically impacts KVM/x86 environments utilizing nested virtualization, posing a significant risk to cloud providers and enterprises.
  • A fix for Zapscape was introduced on July 21, 2026, and organizations are urged to apply vendor kernel updates immediately.

A severe security vulnerability, designated CVE-2026-64561 and dubbed “Zapscape,” has been discovered within the Linux kernel’s Kernel-based Virtual Machine (KVM). This critical flaw enables attackers to break out of a guest virtual machine and seize control of the host system with full root privileges.

Table Of Content

  • Key Takeaways
  • Zapscape KVM Escape Grants Root Access
  • What You Should Do

The issue specifically targets KVM/x86, a widely used virtualization technology responsible for isolating guest operating systems from the physical server hardware. Its implications are particularly grave for cloud service providers and large enterprises that routinely execute untrusted workloads within virtualized environments.

Security researcher Hyunwoo Kim, known by the handle V4bel, is credited with uncovering Zapscape. The vulnerability resides within KVM’s shadow memory management unit (shadow MMU), a component crucial for handling memory translations, especially when nested virtualization is employed.

Nested virtualization facilitates the operation of one virtual machine inside another. While offering benefits for development, testing, and advanced cloud services, this architecture inherently expands the potential attack surface.

Technically, Zapscape is a use-after-free bug located in the recursive zap path that KVM utilizes when reclaiming shadow pages. This means KVM can deallocate a memory structure but subsequently attempt to access or use that now-freed memory, leading to potential corruption.

Zapscape KVM Escape Grants Root Access

An adversarial guest system can trigger this hazardous condition, corrupting host kernel memory and effectively dismantling the security boundary that typically separates a virtual machine from its host. The consequences of a successful exploit are severe: an attacker with kernel-level access within an L1 guest could execute arbitrary commands on the KVM host as root.

Such a breach could facilitate data exfiltration, service interruptions, unauthorized access to other virtual machines residing on the same physical server, or complete control over the host infrastructure. In multi-tenant cloud environments, this means that the compromise of a single customer’s virtual instance could potentially jeopardize the data and operations of other clients sharing the same server.

A proof-of-concept published on GitHub demonstrates the full escape chain in a controlled QEMU TCG environment, culminating in the creation of a root-owned file on the host system. While the researcher notes this PoC is not a ready-to-deploy cloud exploit, they warn that adapting it for real-world environments would not be exceptionally difficult. The public availability of such exploits serves as an urgent call for immediate patching by organizations.

The vulnerable code was initially introduced in 2020. The upstream fix for this issue was committed to the Linux kernel via commit 2abd5287f083 on July 21, 2026. This patch modifies the validation sequence within the shadow MMU fault path. KVM now performs an additional check to determine if a root page has become invalid after making MMU pages available. If the page has been reclaimed, KVM will retry the fault operation instead of proceeding with the invalid memory structure.

The risk associated with Zapscape is highest in scenarios where nested virtualization is exposed to untrusted users. Gaining root access within the guest is generally a prerequisite for the documented escape path, a common condition in many infrastructure-as-a-service (IaaS) deployments.

For Intel-based systems, an additional condition applies: both four-level and five-level Extended Page Table (EPT) page-walk support must be exposed to the L1 guest. This specific requirement does not apply to AMD systems.

What You Should Do

  • Apply Patches Immediately: Administrators must promptly install vendor-provided kernel updates that incorporate the upstream fix for CVE-2026-64561 and reboot all affected KVM hosts.
  • Disable Nested Virtualization: Where operationally feasible, disable nested virtualization for untrusted guests until patching is complete.
  • Restrict /dev/kvm Access: Review and tighten access controls to /dev/kvm on host systems.
  • Review Host Configurations: Conduct a thorough review of KVM host configurations, particularly identifying multi-tenant systems that might be exposed.
  • Monitor Vendor Advisories: Stay vigilant for further advisories and updates from your Linux distribution vendors and hardware providers.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs

Next Post

Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
ChainDrop Worm Steals GitHub, Cloud Credentials via 400+ npm Packages
August 7, 2026
UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us