HispasecAugust 7, 2026🇪🇸Translated from Spanish

Zapscape Flaw in KVM Breaks Nested Virtualization Isolation Allowing L1 Guest Root Code Execution on Linux Host

A security flaw in KVM/x86 within the Linux kernel has highlighted a risk that many infrastructure platforms accept almost without question: nested virtualization exposed to untrusted workloads. The vulnerability, named Zapscape and registered as CVE-2026-64561, can allow an attacker with kernel privileges inside a level-1 virtual machine to execute code on the host with root permissions.

The problem centers on the shadow MMU and the way KVM manages shadow page tables when the L1 guest itself acts as a hypervisor for an L2 guest. In practical terms, the isolation that normally protects the host from activity inside a VM is weakened exactly in the scenario where a provider grants more power to a tenant by allowing nested virtualization inside the tenant’s own VM.

The technical root cause lies in an incorrect ordering when checking a “stale root” condition during guest page-fault handling. This sequence can result in a use-after-free, followed by writes after free — a classic pattern used to turn a memory corruption issue into arbitrary code execution.

Public disclosure includes a proof-of-concept exploit that chains the vulnerability and ultimately creates a file named /Zapscape on the host with root ownership. On Intel platforms the scenario requires the L1 guest to have EPT page walk lengths 4 and 5 exposed. No equivalent condition appears in the published information for AMD processors.

No active exploitation in real-world attacks has been observed so far. Nevertheless, the potential scope justifies rapid action, especially in multi-tenant environments. The NVD lists affected versions starting from Linux 5.9, and fixes are already present in the mainline tree and stable branches, including versions 6.6.148, 6.12.101, 6.18.42, 7.1.6 and 7.2 rc5.

The most direct mitigation is to update to a patched stable kernel or install the vendor package containing the backported fix. At the same time, organizations should inventory hosts that offer nested virtualization to untrusted tenants and treat them as patching priorities. If a server does not require nested virtualization, disabling it immediately reduces the attack surface. Administrators should also verify the effective version through their distribution vendor, because some fixes arrive as backports without obvious changes to the upstream version string.

Related articles

Security NEXTVulnerabilities & Exploits

ServiceNow Patches Multiple Critical Vulnerabilities in Now Platform and AI Platform

ServiceNow disclosed several critical vulnerabilities affecting the Now Platform and ServiceNow AI Platform on August 27. The issues include unauthenticated code injection via the GraphQL Composite Data API, improper access controls during system image uploads, and SQL injection flaws that allow arbitrary database queries. Four CVEs were published: CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. Exploitation of CVE-2026-18885 could permit remote code execution and data manipulation without authentication under certain conditions. CVE-2026-18886 enables unauthorized data creation, modification, and privilege escalation, while CVE-2026-74820 allows direct SQL execution against the underlying database. ServiceNow has released updated versions to address the flaws.

Security NEXTVulnerabilities & Exploits

CISA Adds Linux Kernel Frag Gap Flaw and Two Other Exploited Vulnerabilities to KEV Catalog

The US Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 27, 2026. One of the entries is CVE-2026-53362, a high-severity privilege escalation issue in the Linux kernel also known as Frag Gap. The flaw stems from an out-of-bounds write when generating IPv6 packets, allowing a low-privileged user to obtain root access. The Linux Kernel Organization assigned it a CVSS v3.1 base score of 7.8 and rated it High severity, with public exploit code already available. Federal agencies must remediate CVE-2026-53362 and CVE-2023-49105 by the August 30 deadline. The advisory underscores ongoing exploitation of these issues in the wild.

HispasecVulnerabilities & Exploits

CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalog Including Citrix NetScaler, Linux Kernel and Microsoft SQL Server Flaws

On August 26, 2026, CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling confirmed active exploitation and requiring immediate remediation priority. The batch includes a recent memory corruption issue in Citrix NetScaler ADC and NetScaler Gateway tracked as CVE-2026-8452, along with five older flaws affecting Microsoft SQL Server, the Linux kernel, Ajax.NET Professional, Red Hat libuser, and Red Hat ABRT. Citrix released patches for the NetScaler vulnerability on June 30, 2026, while CISA set an August 29, 2026 deadline for federal agencies. Real-world attacks have already deployed web shells and performed reconnaissance after successful exploitation of the Citrix appliance. The remaining CVEs enable remote code execution, local privilege escalation, and denial-of-service conditions across widely deployed enterprise technologies.

BoletimSecVulnerabilities & Exploits

Next.js Patches Two Critical RCE Vulnerabilities in Versions 15.5.24 and 16.3.3

Next.js has released security updates to address two critical vulnerabilities that could allow unauthenticated remote code execution. The fixes are available in versions 15.5.24 and 16.3.3. The first issue, tracked as CVE-2026-75604 with a CVSS score of 9.0, affects applications hosted on Windows servers using Pages Router or App Router without Cache Components and stems from a path traversal flaw. The second vulnerability impacts the Image Optimization API when processing malicious AVIF files, enabling code execution through crafted image inputs. Both flaws affect a wide range of versions from 10.0.0 and 13.4 onward. Administrators are advised to update immediately, rebuild containers, and verify production environments run the patched releases, especially on Windows systems and those handling user-uploaded images.