A skipped cache invalidation leaves a freed page of host memory mapped and writable for a guest virtual machine on…
CISA added three Linux kernel flaws to its exploited list while a researcher published working root exploits for four more.
CISA added six actively exploited flaws to KEV, including a Citrix NetScaler bug now under attack in the wild.
Zapscape, tracked as CVE-2026-64561, lets a nested KVM guest with kernel privileges escape to the host.
Tencent researchers escaped a container and reached host root through an 18-year-old SCTP use-after-free.
A 13-year-old memory corruption flaw ships with a public exploit covering roughly 800 kernel builds.
The bug was introduced in 2017 via an in-place crypto optimization and remained undetected for nine years, affecting every major…