High 7.0
CVE-2026-64561
Zapscape KVM Guest-to-Host Escape Vulnerability and PoC Release
Vendor / product: Linux KVM
Event date: 2026-08-06
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
Sources & citations (4)
- New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts thehackernews.com · 2026-08-06
- CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges cybersecuritynews.com · 2026-08-07
- Zapscape Is The Latest Linux Vulnerability For KVM Guest-To-Host Escape, LPE phoronix.com · 2026-08-06
- Zapscape, el último y peligroso agujero de seguridad descubierto en Linux: permite a invitados escapar al anfitrión y ejecutar comandos como root computerhoy.20minutos.es · 2026-08-08
References
See CVE-2026-64561 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →