Zapscape, tracked as CVE-2026-64561, lets a nested KVM guest with kernel privileges escape to the host.
Broadcom shipped emergency patches for a critical VM escape vulnerability affecting VMware ESXi, vCenter, and Fusion products.