Securityaffairs.Co Critical Januscape Vulnerability in Linux KVM Exposes Cloud Servers to Attacks
Article Content
- •Januscape (CVE-2026-53359) allows guest VMs to escape and control the host system.
- •The vulnerability has existed for 16 years and affects both Intel and AMD architectures.
- •A patch has been released; administrators must ensure it is applied to secure their systems.
A critical vulnerability in Linux KVM, named Januscape (CVE-2026-53359), has been discovered after lying dormant for 16 years. This flaw allows attackers with root access in a guest virtual machine to escape to the host and execute arbitrary code, affecting both Intel and AMD systems. The vulnerability stems from a use-after-free issue in KVM's shadow MMU emulation, which can lead to host kernel crashes or full control over the host and other guests. The bug was disclosed by researcher Hyunwoo Kim and has been patched as of July 4, 2026. It poses a significant risk to multi-tenant cloud environments, such as those used by major providers like Google Cloud and AWS. Administrators are urged to apply the patch immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (32)
Following this threat?
Track CVE-2022-0847 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Exploitation of Dirty Pipe Vulnerability in Docker Environments CVE-2022-0847, known as Dirty Pipe, is a critical Linux kernel vulnerability that allows local unprivileged users to overwrite data in read-only files, potentially gaining root access. This vulnerability affects Linux kernel versions 5.8 and above. A practical demonstration using Docker has been released to educate…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…