V4bel[verified]@v4belDisclosure
The post announces CVE-2026-64561, detailing a guest‑to‑host escape vulnerability in KVM/x86 and urging immediate patching; no PoC, exploit code, or active exploitation claims are made.
إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediDisclosure
The post announces a new CVE-2026-64561, a KVM privilege‑escalation vulnerability that lets a root‑privileged attacker escape from a guest VM to the host.
dbugs[verified]@ptdbugsPoC
A PoC and exploit code for CVE-2026-64561 have been shared, detailing a KVM root handling flaw, but no evidence of active exploitation or patching is mentioned.
Rıdvan Yağlı[verified]@ridvanyagliPoC
A new critical Linux KVM VM‑escape vulnerability (CVE‑2026‑64561) has been disclosed with a publicly available PoC that enables guest root to escape to host root, but no active exploitation or patch details are reported.
CiberBaur[verified]@BotBauRDisclosure
A newly disclosed Linux kernel flaw (CVE‑2026‑64561) called Zapscape that allows kernel‑level VM escape, with technical details provided and a patch in progress. Administrators are advised to disable nested virtualization until a fix is released.
Ali Saleh[verified]@alisalehimanDisclosure
Announces CVE-2026-64561 (Zapscape) that allows attackers within a nested KVM VM to reach the host if the processor flag is set as Host, and advises updating the kernel and disabling nested virtualization when unnecessary.
Mbuya[verified]@itsmbuyaDisclosure
An undisclosed use‑after‑free flaw (CVE‑2026‑64561) allows a privileged nested VM to escape to the host; no PoC or active attacks yet, but an urgent patch is available.
yousukezan[verified]@yousukezanPoC
A proof‑of‑concept for CVE‑2026‑64561 has been released, demonstrating a use‑after‑free in KVM/x86 Shadow MMU that allows guest code to execute arbitrary code on the host kernel. The PoC code is publicly available on GitHub.