vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
2026-05-07T07:24:07Z•89886d51682008176d1bd1d03201c3ff96af1bff8e6bfc33c30149d258a78937
ADBAPTDAEMON ToolsIoTMOVEitRATScarCruftactive exploitationbotnetcPanelcredential theftincident responsepatchingphishingransomwareremote code executionsandbox escapesupply chainvm2vulnerability
What happened
Multiple high-impact security incidents and disclosures were reported: critical and actively exploited remote code execution and sandbox-escape flaws (notably vm2 sandbox issues, Palo Alto PAN-OS CVE-2026-0300, Apache HTTP/2 CVE-2026-23918, MetInfo CVE-2026-29014, Weaver E-cology CVE-2026-22679) and a Linux local privilege escalation added to CISA KEV (CVE-2026-31431). Widespread supply-chain compromises (DAEMON Tools, ScarCruft trojanized game components), a Mirai-derived xlabs_v1 botnet abusing exposed ADB for IoT enlistment, and active campaigns including MuddyWater using Microsoft Teams, a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 89886d51682008176d1bd1d03201c3ff96af1bff8e6bfc33c30149d258a78937
- Enrichment time
- 2026-05-07T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.