Threat Intelligence

New 'Zapscape' Flaw Could Let Attackers Break Out of Virtual Machines

The Hacker News · 7 Aug 2026
Key Takeaway If your business uses virtual machines or cloud hosting with nested virtualization, check with your provider or IT team about patching this vulnerability as soon as updates become available.

Security researchers have identified a new vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) technology, which many businesses rely on to run virtual machines and cloud services. Tracked as CVE-2026-64561, the flaw—nicknamed 'Zapscape'—affects the shadow memory management unit used in nested virtualization, a setup where one virtual machine runs inside another.

If exploited, an attacker who already has kernel-level privileges inside a nested guest VM could potentially break out of that isolated environment and run code directly on the host machine. This is particularly concerning for cloud providers, hosting companies, and businesses that allow customers or third parties to run their own virtual machines, as it undermines the security boundary that separates one customer's environment from another's.

While exploiting this flaw requires significant existing access (kernel privileges within a guest VM), the risk is real for organisations using nested virtualization with untrusted guests. Patches and mitigations are expected from Linux distribution maintainers as awareness of the flaw spreads, and businesses using virtualization platforms should monitor vendor advisories closely.

Linux Virtualization KVM Vulnerability Cloud Security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.