Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks

2026-07-07T08:51:48Z76df6ef01248893b3e58f482badd4d219fcef90b10a2efe23344f98e03fc365a
adobe-coldfusionai-securitybad-epollcloud-securitycredential-theftcve-2026-46242cve-2026-48282data-breachdata-extortiondevtools-compromiseexploited-in-the-wildfatfsiotkvmlinux-kernellocal-privilege-escalationmedtronicprompt-injectionrceshinyhunterssupply-chainteampcpuse-after-freevirtualizationvm-escape

What happened

Collection of security news covering multiple high-impact issues: a 16-year-old Linux KVM use-after-free (“Januscape”) enabling cloud VM crashes and potential guest-to-host escape on Intel/AMD platforms; active exploitation of a critical Adobe ColdFusion path-traversal RCE (CVE-2026-48282) against unpatched servers; Bad Epoll kernel vulnerability (CVE-2026-46242) allowing local privilege escalation to root on Linux/Android; seven FatFs flaws affecting IoT/embedded devices (memory corruption/crash/data leaks); and new attack techniques (hidden/indirect prompt-injection tricking AI agents into付款

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
76df6ef01248893b3e58f482badd4d219fcef90b10a2efe23344f98e03fc365a
Enrichment time
2026-07-07T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.