CVE-2026-53359Patch(linux / linux_kernel)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 32 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. A similar hole however remains if the modified PDE points to a non-leaf page. In this case the gfn can be made to match, but the role does not match: the original large 2MB page creates a kvm_mmu_page with direct=1, while the new 4KB needs a kvm_mmu_page with direct=0. However, kvm_mmu_get_child_sp() does not compare the role, and therefore reuses the page. The next step is installing a leaf (4KB) SPTE on the new path which records an rmap entry under the gfn resolved by the walk. But when that child is zapped its parent kvm_mmu_page has direct=1 and kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[] in older kernels). It therefore fails to remove the recorded entry. When the memslot is dropped the shadow page is freed but the rmap entry survives, as in the scenario that was already fixed. Code that later walks that gfn (dirty logging, MMU notifier invalidation, and so on) dereferences an sptep that lies in the freed page, causing the use-after-free.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 144 mentions across 34 observed days

What's happening

  • Active exploitation reported across 9 signals
  • Exploit tool or code specified in 18 signals
  • PoC mentioned or linked in 44 signals
  • Patch or workaround mentioned in 74 signals
  • Technical details provided in 101 signals
  • Disclosure: 46 classified signals
  • Peaked 31d ago at 32 mentions (2026-07-07); latest day: 1
  • 144 total mentions across 34 days

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline144 mentions / 34d
08162432Mentions · 2026-07-05: 1Mentions · 2026-07-06: 17Mentions · 2026-07-07: 32Mentions · 2026-07-08: 22Mentions · 2026-07-09: 10Mentions · 2026-07-10: 7Mentions · 2026-07-11: 2Mentions · 2026-07-12: 5Mentions · 2026-07-13: 3Mentions · 2026-07-14: 2Mentions · 2026-07-15: 1Mentions · 2026-07-16: 1Mentions · 2026-07-17: 5Mentions · 2026-07-18: 1Mentions · 2026-07-19: 2Mentions · 2026-07-20: 4Mentions · 2026-07-21: 3Mentions · 2026-07-22: 1Mentions · 2026-07-23: 7Mentions · 2026-07-26: 1Mentions · 2026-07-28: 2Mentions · 2026-08-01: 2Mentions · 2026-08-02: 1Mentions · 2026-08-03: 1Mentions · 2026-08-06: 1Mentions · 2026-08-07: 1Mentions · 2026-08-09: 2Mentions · 2026-08-13: 1Mentions · 2026-08-19: 1Mentions · 2026-08-28: 1Mentions · 2026-08-29: 1Mentions · 2026-08-30: 1Mentions · 2026-09-14: 1Mentions · 2026-09-16: 1PoC Mentioned / Linked · 2026-07-06: 8PoC Mentioned / Linked · 2026-07-07: 11PoC Mentioned / Linked · 2026-07-08: 5PoC Mentioned / Linked · 2026-07-09: 4PoC Mentioned / Linked · 2026-07-10: 2PoC Mentioned / Linked · 2026-07-11: 1PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-07-13: 1PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-07-18: 1PoC Mentioned / Linked · 2026-07-19: 2PoC Mentioned / Linked · 2026-07-20: 1PoC Mentioned / Linked · 2026-07-23: 3PoC Mentioned / Linked · 2026-08-03: 1PoC Mentioned / Linked · 2026-08-06: 1PoC Mentioned / Linked · 2026-08-28: 1Exploit Tool / Code · 2026-07-06: 4Exploit Tool / Code · 2026-07-07: 3Exploit Tool / Code · 2026-07-08: 1Exploit Tool / Code · 2026-07-09: 2Exploit Tool / Code · 2026-07-10: 1Exploit Tool / Code · 2026-07-12: 1Exploit Tool / Code · 2026-07-13: 1Exploit Tool / Code · 2026-07-17: 1Exploit Tool / Code · 2026-07-19: 1Exploit Tool / Code · 2026-07-20: 1Exploit Tool / Code · 2026-08-03: 1Exploit Tool / Code · 2026-08-28: 1Active Exploitation · 2026-07-06: 2Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-07-08: 2Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-07-14: 1Active Exploitation · 2026-07-28: 1Active Exploitation · 2026-08-07: 1Patch / Workaround · 2026-07-06: 7Patch / Workaround · 2026-07-07: 17Patch / Workaround · 2026-07-08: 9Patch / Workaround · 2026-07-09: 5Patch / Workaround · 2026-07-10: 4Patch / Workaround · 2026-07-11: 2Patch / Workaround · 2026-07-12: 4Patch / Workaround · 2026-07-13: 2Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-17: 3Patch / Workaround · 2026-07-19: 1Patch / Workaround · 2026-07-20: 4Patch / Workaround · 2026-07-21: 3Patch / Workaround · 2026-07-22: 1Patch / Workaround · 2026-07-23: 1Patch / Workaround · 2026-07-26: 1Patch / Workaround · 2026-07-28: 1Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-08-30: 1Patch / Workaround · 2026-09-14: 1Patch / Workaround · 2026-09-16: 1Technical Details · 2026-07-06: 12Technical Details · 2026-07-07: 27Technical Details · 2026-07-08: 17Technical Details · 2026-07-09: 7Technical Details · 2026-07-10: 6Technical Details · 2026-07-11: 1Technical Details · 2026-07-12: 3Technical Details · 2026-07-13: 2Technical Details · 2026-07-14: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-17: 3Technical Details · 2026-07-18: 1Technical Details · 2026-07-19: 2Technical Details · 2026-07-20: 3Technical Details · 2026-07-23: 4Technical Details · 2026-07-26: 1Technical Details · 2026-07-28: 2Technical Details · 2026-08-03: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-28: 1Technical Details · 2026-08-29: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-16: 107-0507-0807-1107-1407-1707-2007-2308-0108-0608-1308-2909-16
Signal classification6 categories
Patch
5236.1%
Disclosure
4631.9%
PoC
2316.0%
General
117.6%
Exploit
74.9%
Active Exploitation
53.5%
Referenced assets76 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-051
Disclosure1
2026-07-0617
Active Exploitation2Disclosure4General2Patch2PoC7
2026-07-0732
Disclosure14Exploit2General1Patch12PoC3
2026-07-0822
Active Exploitation1Disclosure8General3Patch8PoC2
2026-07-0910
Disclosure1General1Patch4PoC4
2026-07-107
Disclosure1Exploit1General1Patch4
2026-07-112
Patch1PoC1
2026-07-125
Disclosure1Patch3PoC1
2026-07-133
Exploit1Patch2
2026-07-142
Active Exploitation1Patch1
2026-07-151
General1
2026-07-161
Patch1
2026-07-175
Disclosure1Exploit1Patch3
2026-07-181
Disclosure1
2026-07-192
Disclosure1Exploit1
2026-07-204
Disclosure2Patch2
2026-07-213
Patch3
2026-07-221
Patch1
2026-07-237
Disclosure3Patch1PoC3
2026-07-261
Patch1
2026-07-282
Active Exploitation1Disclosure1
2026-08-012
Disclosure1General1
2026-08-021
Disclosure1
2026-08-031
PoC1
2026-08-061
PoC1
2026-08-071
Disclosure1
2026-08-092
Disclosure1General1
2026-08-131
Patch1
2026-08-191
Disclosure1
2026-08-281
Exploit1
2026-08-291
Disclosure1
2026-08-301
Patch1
2026-09-141
Patch1
2026-09-161
Disclosure1
Full discourse20 posts
  • International Cyber Digest@IntCyberDigest
    PoC

    ‼️ A 16-year-old Linux KVM vulnerability called Januscape (CVE-2026-53359) lets a root user inside a guest VM escape to the host on Intel and AMD x86 systems, and a proof of concept that crashes hosts is already public. Canonical says patched Ubuntu kernels are still pending for all releases and recommends disabling nested virtualization in the meantime.

    Post summary

    A new 16‑year‑old Linux KVM vulnerability (CVE‑2026‑53359) allows root inside a guest VM to escape to the host; a public PoC exists, while patching is still pending and disabling nested virtualization is advised.

    45278343.0K888350.8K
    217.8K followersView on X
  • V4bel@v4bel
    Active Exploitation

    💥 Introducing "Januscape" (CVE-2026-53359) A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU. Triggerable on both Intel and AMD hosts. Threatens x86 public clouds (GCP, AWS) that expose nested virtualization. "16 years" latent. Successfully used as a 0-day exploit in "Google kvmCTF". To the best of public knowledge, the first KVM exploit research triggerable on both Intel and AMD. Details: https://januscape.io

    Post summary

    CVE‑2026‑53359, dubbed Januscape, is a guest‑to‑host escape vulnerability that has already been actively exploited as a zero‑day during a Google KVM CTF, posing a threat to nested virtualization in public clouds.

    7104845121861.9K
    3.9K followersView on X
  • The Hacker News@TheHackersNews
    PoC

    🔥 A new 16-year-old #Linux KVM flaw lets a rooted nested VM crash the x86 host and take down other tenants on the same machine. Dubbed "Januscape" (CVE-2026-53359), the bug sits in KVM’s shadow MMU. Researcher says a full guest-to-host escape exploit also exists in a controlled setup; only the host-crash PoC is public. Explained here: https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html

    Post summary

    A host‑crash proof of concept for CVE‑2026‑53359 (a KVM shadow MMU flaw) is publicly disclosed, while an additional guest‑to‑host escape exploit exists only in controlled environments.

    96812084646.5K
    2.3M followersView on X
  • Octave Klaba@olesovhcom
    Patch

    Nous avons terminé la compagne de patching du jbug critique CVE-2026-53359 dans KVM. Vu le niveau critique du bug, nous n'avons pas communiqué avant de démarrer le patching, il fallait aller vite. Maintenant que l'infra est en sécurité, voici le REX. https://blog.ovhcloud.com/campagne-de-patch-de-la-cve-2026-53359-januscape-retour-dexperience-sur-le-traitement-dune-faille-kvm-sur-plusieurs-dizaines-de-milliers-de-machines/

    Post summary

    OVHcloud has finished the patch campaign for the critical CVE‑2026‑53359 in KVM and shares a post‑incident review, confirming the issue was addressed but providing no exploitation details.

    104071728236.1K
    80.8K followersView on X
  • 1024@1024DevHub
    Disclosure

    KVM Januscape 漏洞:虚拟机可逃逸宿主机,潜伏 16 年 安全研究人员公开了 Januscape(CVE-2026-53359)漏洞,这是首个能同时在 Intel 与 AMD 平台上触发的 KVM/x86 虚拟机逃逸漏洞。该漏洞源于 shadow MMU 模拟中的 use-after-free 缺陷,客户机仅通过内部操作即可破坏宿主机内核的 shadow page,直接威胁公有云等多租户 KVM 宿主机的隔离边界。 该漏洞影响范围横跨 2010 年至 2026 年 6 月,在 Linux 内核中潜伏约 16 年,曾被用作 Google kvmCTF 的 0-day 攻击。其 PoC 代码已发布,可在客户机内触发宿主机内核 panic。此外,在 RHEL 等发行版中,本地普通用户还可利用该缺陷提权至 root。 https://github.com/V4bel/Januscape

    Post summary

    CVE‑2026‑53359, a 16‑year‑old KVM virtualization escape due to a shadow‑MMU use‑after‑free, has been disclosed with PoC code available on GitHub; the flaw can crash the host kernel and enable local privilege escalation.

    122112510034.5K
    19.5K followersView on X
  • Cyber Security News@The_Cyber_News
    Disclosure

    16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory Source: https://cybersecuritynews.com/16-year-old-linux-kvm-vulnerability/ A newly disclosed Linux Kernel-based Virtual Machine (KVM) vulnerability, tracked as CVE-2026-53359 and dubbed “Januscape,” exposes a critical flaw that allows a malicious guest to corrupt host kernel memory, breaking the fundamental isolation guarantees of virtualization. The issue, which remained unnoticed for nearly 16 years, affects KVM’s x86 shadow memory management logic and impacts both Intel and AMD systems. The vulnerability resides in KVM’s shadow MMU (Memory Management Unit), specifically in its handling of nested virtualization. #cybersecuritynews

    Post summary

    A 16‑year‑old Linux KVM vulnerability (CVE‑2026‑53359, Januscape) has been disclosed, describing a flaw in the shadow MMU that permits a malicious guest to corrupt host kernel memory and break isolation. The report does not provide a PoC, exploit, active exploitation evidence, or patch information.

    53001533210.3K
    72.8K followersView on X
  • mintbot@mintbot_ai
    Patch

    𝗤𝘂𝗶𝗰𝗸 𝗿𝗲𝘀𝘁𝗮𝗿𝘁 𝘁𝗼𝗱𝗮𝘆 🔧 — blame a two-faced Roman god Our server provider is rebooting some machines today to patch a fresh bug called 𝗝𝗮𝗻𝘂𝘀𝗰𝗮𝗽𝗲 (CVE-2026-53359) — too elegant not to share: • It's a 𝗴𝘂𝗲𝘀𝘁-𝘁𝗼-𝗵𝗼𝘀𝘁 𝗲𝘀𝗰𝗮𝗽𝗲 — a bug that lets a VM (like the ones mintbot runs on 🙋) climb up to its hypervisor. The exact nightmare that keeps cloud providers awake. • Named after 𝗝𝗮𝗻𝘂𝘀, the two-faced god, because it fires on 𝗯𝗼𝘁𝗵 𝙄𝙣𝙩𝙚𝙡 𝗮𝗻𝗱 𝘼𝙈𝘿 — most bugs pick a side; this one looks both ways. • It hid in Linux's KVM code for ~𝟭𝟲 𝘆𝗲𝗮𝗿𝘀, and was even used as a 𝟬-𝗱𝗮𝘆 𝗮𝘁 𝗚𝗼𝗼𝗴𝗹𝗲'𝘀 𝗸𝘃𝗺𝗖𝗧𝗙 before going public. Nothing needed on your end — we'll be back within minutes. And nobody's climbing to the hypervisor floor today. 😼 #infosec #kvm #CVE202653359

    Post summary

    The post announces that the server provider is rebooting machines to apply a patch for CVE‑2026‑53359, a guest‑to‑host escape in KVM that has been a 0‑day for years but is not reported as currently being exploited.

    114305501.1K
    1.7K followersView on X
  • cr3ghost@cr3ghost
    Exploit

    A KVM escape vulnerability that has been dormant for 16 years. Guest-to-host. Works on both Intel and AMD. The first public research to achieve that. Januscape (CVE-2026-53359) is a use-after-free in KVM's shadow MMU emulation. Guest-side actions alone can corrupt the host kernel's shadow pages. A single rented cloud instance could panic every other tenant VM on the same physical host, or achieve full RCE on the host with root. Successfully exploited as a 0-day in Google kvmCTF. Affects every x86 KVM host since 2010. On RHEL, /dev/kvm is world-writable. This also works as an unprivileged LPE to root. https://www.openwall.com/lists/oss-security/2026/07/06/7 https://github.com/V4bel/Januscape Author: @v4bel #ExploitDevelopment #LinuxSecurity #InfoSec

    Post summary

    A KVM escape CVE‑2026‑53359 has a publicly available PoC and exploit code that has been demonstrated in a 0‑day CTF, showing real‑world potential across all x86 KVM hosts, but no patch or mitigation has yet been disclosed.

    117042244.4K
    7.8K followersView on X
  • Linux Kernel Security@linkersec
    Disclosure

    Januscape: Guest-to-Host Escape in KVM/x86 @v4bel published an article about a use-after-free vulnerability in the shadow MMU emulation of KVM/x86 (CVE-2026-53359). Both Intel (VMX) and AMD (SVM) code is affected. https://github.com/V4bel/Januscape/blob/main/assets/write-up.md https://t.co/ecIO9ofVwr

    Post summary

    The tweet announces a use‑after‑free flaw (CVE‑2026‑53359) in KVM’s shadow MMU on both Intel and AMD platforms, providing a link to a write‑up with technical details.

    19027173.1K
    10.5K followersView on X
  • AlmaLinux@AlmaLinux
    Patch

    We have two patched kernels ready for testing: Januscape (CVE-2026-53359) and Bad Epoll (CVE-2026-46242). Januscape affects every supported AlmaLinux release (8, 9, and 10). Bad Epoll affects AlmaLinux 9 and 10. Learn more ⤵️ https://almalinux.org/blog/2026-07-06-januscape-bad-epoll/?utm_medium=social&utm_source=twitter

    Post summary

    The tweet announces that patched kernels for CVE-2026-53359 and CVE-2026-46242 are ready for testing on AlmaLinux and directs readers to a blog post for details.

    11013833.7K
    12.5K followersView on X
  • eSIMuse|AI 通信指南@esimuse
    Disclosure

    一个潜伏了16年的KVM漏洞,比绝大多数VPS商家的成立时间都长。 CVE-2026-53359,use-after-free,虚拟机逃逸到宿主机。 很多vps厂家已经在修了。 如果你最近VPS莫名其妙重启了,别急着骂商家跑路,可能是这玩意儿。

    Post summary

    A 16‑year‑old KVM use‑after‑free vulnerability (CVE‑2026‑53359) allows VM escape to the host; many VPS providers have issued patches, and users may observe unexplained restarts due to active exploitation.

    41120199.8K
    4.0K followersView on X
  • 7h3h4ckv157@7h3h4ckv157
    PoC

    CVE-2026-53359: discovered and reported by Hyunwoo Kim. It is a KVM escape vulnerability that lets a guest escape to the host in a KVM/x86 environment Source: https://github.com/V4bel/Januscape https://t.co/letMkMy6x4

    Post summary

    CVE-2026-53359 is a KVM escape vulnerability with an available PoC on GitHub, but no evidence of active exploitation or patch.

    1802442.3K
    56.9K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    🚨 A Long-Lived KVM Bug Resurfaces: Shadow Paging Use-After-Free in the Linux Kernel (CVE-2026-53359) https://darkwebinformer.com/a-long-lived-kvm-bug-resurfaces-shadow-paging-use-after-free-in-the-linux-kernel-cve-2026-53359/

    Post summary

    The post announces a resurfacing KVM use‑after‑free bug in the Linux kernel (CVE‑2026‑53359) but provides no PoC, exploit code, or active exploitation details.

    03020129.5K
    233.2K followersView on X
  • Adrien Linuxtricks @_adriend_
    Disclosure

    Pour info, la faille #Januscape (CVE-2026-53359) est une faille de type guest-to-host sur KVM ! Elle permet d'agir (ici un DoS) sur l'hôte hyperviseur depuis une machine invité ! Evidemment OLVM, Proxmox, OVirt, etc reposant sur KVM sont vulnérables ! https://cybersecuritynews.com/16-year-old-linux-kvm-vulnerability/

    Post summary

    CVE-2026-53359 is a newly disclosed guest-to-host vulnerability in KVM that enables a denial-of-service attack from a guest VM to the host hypervisor, affecting KVM‑based platforms such as OVM, Proxmox, and OVirt.

    0702121.5K
    6.4K followersView on X
  • real aloy@rimisback
    Disclosure

    $BB Why BlackBerry QNX @QNX_News Matters.... Linux KVM Cannot Anchor an ASIL D Safety Case A sixteen-year-old kernel bug shows why a cloud hypervisor cannot enforce vehicle safety isolation. A newly disclosed Linux KVM vulnerability, tracked as CVE-2026-53359 and reported under the name Januscape, lets a malicious guest virtual machine corrupt host kernel memory. The researcher who found it reports that a controlled guest-to-host escape is achievable, not just a crash. For a cloud operations team, that is a serious but familiar kind of event. For a software-defined vehicle team, it is something else entirely. If a hypervisor like KVM sits inside the boundary separating an ASIL D safety function from everything else running on the same compute platform, a guest-to-host escape is not a patching event. It is evidence that the boundary itself cannot be trusted, and no amount of fast remediation changes that underlying fact. https://automotivecloudwatch.substack.com/p/linux-kvm-cannot-anchor-an-asil-d

    Post summary

    The text announces a new KVM vulnerability (CVE‑2026‑53359, Januscape) that enables a malicious guest VM to corrupt host memory and escape control, highlighting a serious safety boundary issue.

    0522011.3K
    988 followersView on X
  • dbugs@ptdbugs
    Exploit

    Three high-profile Linux kernel studies published recently Within a short period, three independent research projects were released as part of Google CTF's program, each focused on critical flaws in core Linux subsystems: GhostLock (CVE-2026-43499 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-43499)) — a vulnerability in the futex priority inheritance ("rt_mutex") mechanism. A logic flaw in the waiter cleanup routines leads to a stack use-after-free: the kernel continues to operate on an object that has already been freed from the stack. The researchers turned this primitive into a nearly reliable local privilege escalation (LPE) and container escape (≈97% success rate). The bug had existed for about 15 years and was discovered through Google kernelCTF. PT ID: PT-2026-42456 https://dbugs.ptsecurity.com/vulnerability/PT-2026-42456 Bad Epoll (CVE-2026-46242 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-46242)) — a synchronization bug in the "epoll" subsystem causes a heap use-after-free. Despite the race window being only a few instructions long, the researchers developed a nearly ≈99% reliable exploit for local privilege escalation on Linux and Android. This work was also conducted under Google kernelCTF. Januscape (CVE-2026-53359 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-53359)) — a use-after-free vulnerability in KVM Shadow MMU. KVM continues to use a Shadow MMU object after it has been freed, allowing a guest VM to modify Shadow MMU data and execute code in the host kernel context. Unlike the previous two, this is a VM escape, rather than a classic LPE. The research was part of Google kvmCTF. Article 1 (GhostLock): https://nebusec.ai/research/ionstack-part-2/ Article 2 (BadEpoll): https://github.com/J-jaeyoung/bad-epoll Article 3 (Januscape): https://github.com/V4bel/Januscape #dbugs_attacks

    Post summary

    Three recent Google kernelCTF studies reveal critical Linux kernel bugs with near‑perfect exploitability, providing public code and research links for exploitation.

    000146953
    3.4K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    Januscape (CVE-2026-53359) : une faille use-after-free restée 16 ans dans KVM. Louez un VPS, activez la virtu imbriquée côté hôte, et une seule VM peut faire tomber l'hôte + toutes les VM voisines. À patcher 👇 https://www.it-connect.fr/januscape-faille-kvm-evasion-vm-hote/ #linux https://t.co/nIcDY8we9m

    Post summary

    The tweet alerts users to a long‑standing use‑after‑free vulnerability in KVM capable of crashing the host via a single nested VM, and directs them to the relevant patch.

    170921.3K
    11.6K followersView on X
  • exe.dev@ssh_exe_dev
    Patch

    While we validate a kernel change for januscape (CVE-2026-53359), we have disable nested KVM across our fleet for individuals and teams without dedicated hardware. We will restore nested KVM in a rolling release as soon as we can. Apologies for the inconvenience.

    Post summary

    The organization is applying a workaround by disabling nested KVM to mitigate CVE‑2026‑53359, with plans to re‑enable it as a future update arrives.

    0001612.8K
    3.2K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    Researchers disclosed a PoC for the Januscape KVM escape (CVE-2026-53359). This use-after-free KVM bug impacts public clouds, allowing host panics and LPE. #Januscape #KVMEscape #CVE202653359 #CyberSecurity #0day http://securityonline.info/januscape-kvm-escape-cve-2026-53359-poc/

    Post summary

    Researchers disclosed a PoC and code for CVE-2026-53359, a use‑after‑free KVM bug that can trigger host panics and privilege escalation, with no evidence presented of current active exploitation.

    0301031.3K
    12.9K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    The Januscape CVE-2026-53359 vulnerability allows guest VMs to escape to the Linux KVM host kernel, causing DoS or code execution. #Januscape #CVE202653359 #LinuxKVM #Cybersecurity #Vulnerability http://meterpreter.org/januscape-cve-2026-53359-kvm-vulnerability/

    Post summary

    The Januscape CVE‑2026‑53359 vulnerability allows KVM guest VMs to escape to the host kernel, potentially leading to DoS or code execution, and a linked page implies a PoC may exist.

    021110754
    12.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more