Zapscape, tracked as CVE-2026-64561, lets a nested KVM guest with kernel privileges escape to the host.