Zapscape Flaw in KVM Breaks Nested Virtualization Isolation Allowing L1 Guest Root Code Execution on Linux Host
A security flaw in KVM/x86 within the Linux kernel has highlighted a risk that many infrastructure platforms accept almost without question: nested virtualization exposed to untrusted workloads. The vulnerability, named Zapscape and registered as CVE-2026-64561, can allow an attacker with kernel privileges inside a level-1 virtual machine to execute code on the host with root permissions.
The problem centers on the shadow MMU and the way KVM manages shadow page tables when the L1 guest itself acts as a hypervisor for an L2 guest. In practical terms, the isolation that normally protects the host from activity inside a VM is weakened exactly in the scenario where a provider grants more power to a tenant by allowing nested virtualization inside the tenant’s own VM.
The technical root cause lies in an incorrect ordering when checking a “stale root” condition during guest page-fault handling. This sequence can result in a use-after-free, followed by writes after free — a classic pattern used to turn a memory corruption issue into arbitrary code execution.
Public disclosure includes a proof-of-concept exploit that chains the vulnerability and ultimately creates a file named /Zapscape on the host with root ownership. On Intel platforms the scenario requires the L1 guest to have EPT page walk lengths 4 and 5 exposed. No equivalent condition appears in the published information for AMD processors.
No active exploitation in real-world attacks has been observed so far. Nevertheless, the potential scope justifies rapid action, especially in multi-tenant environments. The NVD lists affected versions starting from Linux 5.9, and fixes are already present in the mainline tree and stable branches, including versions 6.6.148, 6.12.101, 6.18.42, 7.1.6 and 7.2 rc5.
The most direct mitigation is to update to a patched stable kernel or install the vendor package containing the backported fix. At the same time, organizations should inventory hosts that offer nested virtualization to untrusted tenants and treat them as patching priorities. If a server does not require nested virtualization, disabling it immediately reduces the attack surface. Administrators should also verify the effective version through their distribution vendor, because some fixes arrive as backports without obvious changes to the upstream version string.
Related articles
Automated Pentesting and BAS: How AI Systems Like XBOW Outpace Human Researchers in Vulnerability Discovery
The article explores how automated penetration testing and Breach and Attack Simulation tools have evolved to provide continuous validation of security controls beyond annual manual pentests. It explains the distinction between BAS, which tests individual attack techniques against security tools using frameworks like MITRE ATT&CK, and autopentest solutions that build complete attack paths to critical assets. Russian vendor Positive Technologies released PT Dephaze 3.0 in October 2025, incorporating machine learning for controlled internal pentesting and earning the National Runet Award. Globally, AI-driven systems demonstrated superior performance, with XBOW topping HackerOne rankings by discovering over 1,000 vulnerabilities including 54 critical ones in just 90 days. Google’s Big Sleep project, combining DeepMind and Project Zero, identified and helped patch CVE-2025-6965 in SQLite before widespread exploitation. These developments underscore the need to integrate automated validation into vulnerability management processes under the emerging CTEM framework.
Critical SSRF Vulnerability Affects SonicWall SMA1000 Series Remote Access Appliances
SonicWall has disclosed four vulnerabilities in its SMA1000 series remote access products, with one rated critical. The most severe issue, CVE-2026-102255, is a server-side request forgery flaw in the WorkPlace interface that allows unauthenticated attackers to abuse the appliance as a forward proxy and reach internal functions. The vulnerability received the maximum CVSSv3.0 base score of 10.0. Two additional flaws, CVE-2026-102256 and CVE-2026-102257, enable authenticated OS command injection and unauthenticated path traversal via crafted archives, respectively. No exploitation has been observed in the wild at the time of disclosure. SonicWall has released updates to address all issues.
WordPress 7.1.3 Security Release Fixes Seven Vulnerabilities Including Stored XSS and SQL Injection
The WordPress development team has released version 7.1.3 as a maintenance and security update addressing multiple vulnerabilities. The release includes seven security fixes and four additional bug corrections. Among the security issues resolved is a stored cross-site scripting flaw that allowed pending comments to execute scripts in the administrative interface. Other fixes cover a denial-of-service condition in URL handling, an SQL injection vulnerability in the WXR export feature, and unauthorized disclosure of comments attached to private or unpublished posts. Additional patches address an XSS issue in the Imgur embed functionality, improper sticky post permissions for users with the Author role, and a parameter manipulation problem affecting hook action names.
Google Releases Chrome 155 Fixing 247 Vulnerabilities Including Four Critical Use-After-Free Flaws
Google has released Chrome 155 on October 6, 2026, addressing a total of 247 security issues across Windows, macOS, and Linux platforms. The update includes four critical vulnerabilities, all classified as use-after-free flaws that affect Chromecast, Browser, Navigation, and Track components. Fifty-three high-severity issues were also resolved, covering problems in SiteIsolation, Core, Omnibox, FileSystem, ANGLE, WebGL, and multiple other modules. The critical CVEs fixed are CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347. Additional fixes address use-after-free conditions, race conditions, type confusion, and integer overflows in V8, WebRTC, PDF, Media, Parser, Storage, and WebAudio. The new versions are Chrome 155.0.8059.40 for Windows and macOS and 155.0.8059.39 for Linux and macOS.