Zapscape Flaw in KVM Breaks Nested Virtualization Isolation Allowing L1 Guest Root Code Execution on Linux Host
A security flaw in KVM/x86 within the Linux kernel has highlighted a risk that many infrastructure platforms accept almost without question: nested virtualization exposed to untrusted workloads. The vulnerability, named Zapscape and registered as CVE-2026-64561, can allow an attacker with kernel privileges inside a level-1 virtual machine to execute code on the host with root permissions.
The problem centers on the shadow MMU and the way KVM manages shadow page tables when the L1 guest itself acts as a hypervisor for an L2 guest. In practical terms, the isolation that normally protects the host from activity inside a VM is weakened exactly in the scenario where a provider grants more power to a tenant by allowing nested virtualization inside the tenant’s own VM.
The technical root cause lies in an incorrect ordering when checking a “stale root” condition during guest page-fault handling. This sequence can result in a use-after-free, followed by writes after free — a classic pattern used to turn a memory corruption issue into arbitrary code execution.
Public disclosure includes a proof-of-concept exploit that chains the vulnerability and ultimately creates a file named /Zapscape on the host with root ownership. On Intel platforms the scenario requires the L1 guest to have EPT page walk lengths 4 and 5 exposed. No equivalent condition appears in the published information for AMD processors.
No active exploitation in real-world attacks has been observed so far. Nevertheless, the potential scope justifies rapid action, especially in multi-tenant environments. The NVD lists affected versions starting from Linux 5.9, and fixes are already present in the mainline tree and stable branches, including versions 6.6.148, 6.12.101, 6.18.42, 7.1.6 and 7.2 rc5.
The most direct mitigation is to update to a patched stable kernel or install the vendor package containing the backported fix. At the same time, organizations should inventory hosts that offer nested virtualization to untrusted tenants and treat them as patching priorities. If a server does not require nested virtualization, disabling it immediately reduces the attack surface. Administrators should also verify the effective version through their distribution vendor, because some fixes arrive as backports without obvious changes to the upstream version string.
Related articles
NEOMSA APIM 4.6.0 Eliminates All Critical and High Vulnerabilities Registered in FSTEC BDU
Neoflex has released NEOMSA APIM 4.6.0 with a primary focus on strengthening the security of the platform's supply chain. The team generated an SBOM in CycloneDX format, scanned components and dependencies using Grype, and cross-referenced findings against the FSTEC BDU database. This process reduced total registered vulnerabilities from 57 to 7, completely removing all 10 Critical and 24 High issues. The platform now meets the formal Security Gate criterion requiring zero Critical or High vulnerabilities from the FSTEC database in the final build. Remaining Medium findings are documented and tracked for future updates. The release provides customers with a verified, transparent component inventory that simplifies compliance and integration reviews.
Cisco Publishes 12 Security Advisories Fixing Critical Flaws in Catalyst SD-WAN and IOS XE
Cisco Systems released 12 new security advisories on August 5, 2026, disclosing a total of 23 vulnerabilities across multiple products. Two advisories covering Cisco Catalyst SD-WAN Software and Cisco IOS XE Software received the highest Critical severity rating. The SD-WAN advisory addresses five issues, including CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each scoring 9.9 on CVSSv3.1. The IOS XE advisory details seven vulnerabilities, with CVE-2026-20272 rated 9.8 and CVE-2026-20267 rated 9.0. Additional advisories cover flaws in Integrated Management Controller, RoomOS, and Terminal Services Agent. Organizations are urged to apply the hardening releases immediately to mitigate remote exploitation risks.
Head Mare Hackers Exploit TrueConf Servers to Distribute PhantomCore and PhantomGraph Backdoors
Russian organizations have been targeted in a new campaign by the Head Mare group, which compromises unpatched TrueConf servers to deliver backdoors. Attackers chain vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with maximum privileges on affected servers. They then replace a server file with a web shell to explore the victim's infrastructure, access the TrueConf database, and substitute the client installer. Victims are tricked via social engineering into downloading the malicious client during video conferences without any suspicious emails. The campaign affects TrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. Kaspersky researchers recommend immediate updates to patched versions 5.3.9, 5.4.9, and 5.5.5 released on 18 June 2026. The threat extends beyond direct TrueConf users, as any employee invited to a compromised server can inadvertently install the backdoor.
Cisco Patches Seven Critical IOS XE Vulnerabilities Including CVSS 9.8 Command Injection Flaw
Cisco has released security updates to address seven vulnerabilities in IOS XE, the operating system powering routers, switches, wireless controllers, and other enterprise network devices. The highest-severity issue, tracked as CVE-2026-20272 with a CVSS score of 9.8, stems from improper handling of special elements in commands and could enable remote command injection, unauthorized operations, and full device compromise over the network. Additional flaws impact memory management, resource lifecycle, numeric calculations, execution flow, and input validation, potentially leading to buffer overflows, out-of-bounds writes, crashes, infinite loops, and directory traversal. The vulnerabilities affect IOS XE versions 17.9, 17.12, 17.15, 17.18, and 26.1 in both standalone and controller modes regardless of configuration. Fixed releases include 17.9.10, 17.12.8, 17.15.6, 17.18.4, 17.18.4a, and 26.1.2, with no available workarounds. The issues were discovered during internal testing that incorporated advanced AI models, and no evidence of public exploitation has been observed.