16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
2026-07-06T19:24:09Z•7d5b5f9cdbcd6907909a408d6883123216cdbd3050873bd6b5b353e650bcd165
CVE-2025-5777CVE-2026-20896CVE-2026-46242CVE-2026-53359Januscapeair-gap-exfiltrationauth-bypassavalonbad-epollcitrix-bleed-2dockerembedded-devicesfatfsgiteaguest-to-host escapekvmlinux-kernelmalware-frameworks','skillcloak','ai-agent-threats','pamstealer'npm-malwarepolinriderquimaratransomwareratsupply-chaintrojpix
What happened
A collection of high-impact security stories: a 16-year-old use-after-free in KVM (Januscape, CVE-2026-53359) can allow guest-to-host escapes on Intel/AMD x86 with a public PoC and claimed unreleased exploit; threat actors began probing a critical Gitea Docker auth-bypass (CVE-2026-20896, CVSS 9.8) within two weeks of disclosure; and a local Linux kernel privilege-escalation (Bad Epoll, CVE-2026-46242) affecting desktops, servers and Android was disclosed and patched. Ransomware actors continue to leverage known flaws and stolen credentials (including Citrix Bleed 2, CVE-2025-5777) for initial
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 7d5b5f9cdbcd6907909a408d6883123216cdbd3050873bd6b5b353e650bcd165
- Enrichment time
- 2026-07-06T19:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.