July 7, 2026
- "Januscape" (CVE-2026-53359) is a use-after-free in the shadow-MMU code shared across Intel and AMD in Linux's KVM hypervisor, triggerable from a guest VM to corrupt host-kernel shadow-page state — a 16-year-old bug enabling guest-to-host escape. The public PoC panics the host; the researcher claims a separate, unreleased exploit goes further, per The Hacker News. · Vulnerabilities & Exploits
in A 16-Year-Old KVM Flaw Punches Through the Hypervisor Boundary