KVM is a technology platform tracked across 8 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity July 8, 2026.
KVM (Kernel-based Virtual Machine) is a Linux kernel virtualization framework that turns the Linux kernel into a hypervisor, enabling multiple guest virtual machines to run on a single host with near-native performance. It is widely used in data centers, clouds, and virtualization workflows. In cybersecurity, KVM-related vulnerabilities, misconfigurations, or VM escape risks can lead to privilege escalation and compromise of the host or other VMs, making KVM a notable surface for threat actors and a focus for hardening.
A critical vulnerability in Linux KVM, named Januscape (CVE-2026-53359), has been discovered after lying dormant for 16 years. This flaw allows attackers with root access in a guest virtual machine to escape to the host…
On July 6, 2026, Oracle released multiple important security advisories for its Linux kernel across various versions, including Oracle Linux 7, 8, and 9. The advisories address critical vulnerabilities in the kernel…
During the Pwn2Own Berlin 2026 event, held from May 14 to 16, security researchers exploited numerous zero-day vulnerabilities, earning over $900,000 in cash prizes. On the first day, 24 unique vulnerabilities were…
SonicWall has issued a security advisory regarding a critical vulnerability in its SonicOS operating system, identified as CVE-2025-40601. This high-severity flaw affects Gen7 and Gen8 hardware and virtual appliances,…
Two vulnerabilities have been reported affecting KVM and Intel performance monitoring features. CVE-2025-23141 involves acquiring SRCU in KVM_GET_MP_STATE to protect guest memory accesses, while CVE-2025-37936 addresses…
CVE-2026-53325 is a critical vulnerability in the Linux kernel's AMD64 AGP driver, caused by improper error handling in the agp_amd64_probe() function. This flaw can lead to a NULL pointer dereference and General…
Several vulnerabilities were identified in the Linux kernel affecting various architectures and subsystems. These vulnerabilities could allow attackers to compromise systems running affected versions of the kernel.…
SonicWall has disclosed a critical vulnerability in its SonicOS SSLVPN service, tracked as CVE-2025-40601, which allows remote, unauthenticated attackers to crash Gen7 and Gen8 firewalls. The flaw, caused by a…