vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution

2026-05-07T07:24:07Z89886d51682008176d1bd1d03201c3ff96af1bff8e6bfc33c30149d258a78937
ADBAPTDAEMON ToolsIoTMOVEitRATScarCruftactive exploitationbotnetcPanelcredential theftincident responsepatchingphishingransomwareremote code executionsandbox escapesupply chainvm2vulnerability

What happened

Multiple high-impact security incidents and disclosures were reported: critical and actively exploited remote code execution and sandbox-escape flaws (notably vm2 sandbox issues, Palo Alto PAN-OS CVE-2026-0300, Apache HTTP/2 CVE-2026-23918, MetInfo CVE-2026-29014, Weaver E-cology CVE-2026-22679) and a Linux local privilege escalation added to CISA KEV (CVE-2026-31431). Widespread supply-chain compromises (DAEMON Tools, ScarCruft trojanized game components), a Mirai-derived xlabs_v1 botnet abusing exposed ADB for IoT enlistment, and active campaigns including MuddyWater using Microsoft Teams, a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
89886d51682008176d1bd1d03201c3ff96af1bff8e6bfc33c30149d258a78937
Enrichment time
2026-05-07T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.