Critical vm2 sandbox bug lets attackers execute code on hosts

2026-05-06T19:23:33Z1a20cef5cb682d0a337986c9ea3156afdf59a42a95b27f9e28930b393d919be3
AcronisChaos ransomwareCiscoDAEMON ToolsInstructure breach claim','student-TETRA-rail-attack','Kochava-­Linux malwareMuddyWaterNode.jsPAN-OSPalo AltoQuasar LinuxVimeobackdoorbackupsdata-breachdenial-of-servicefirewallransomwarereboot-requiredremote-code-executionsandbox-escapesupply-chaintrojanized-installervm2zero-day

What happened

Multiple high-impact incidents and zero-days reported: a critical vm2 Node.js sandbox vulnerability allows sandbox escape and arbitrary host code execution; Palo Alto Networks warns of an actively exploited PAN-OS User-ID Authentication Portal RCE zero-day; DAEMON Tools installers were trojanized in a supply-chain attack delivering a backdoor; and Cisco patched a DoS that requires manual reboot to recover. Other notable stories include a new Quasar Linux implant targeting developers, MuddyWater using Chaos ransomware as a decoy, large data theft claims at Instructure and a Vimeo breach, FTC's措

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
1a20cef5cb682d0a337986c9ea3156afdf59a42a95b27f9e28930b393d919be3
Enrichment time
2026-05-06T19:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.