News
Zapscape KVM Flaw Lets Guest VMs Seize Host Root via Shadow MMU Use-After-Free
Zapscape (CVE-2026-64561) is a use-after-free in KVM's shadow MMU that lets a root-privileged guest escape nested virtualization and execute code as root on the host. The exploit works on both Intel and AMD, and a full proof-of-concept is public.
Read more →