Tag: virtualization
7 articles

VMware vCenter Vulnerability Exploited for Persistent Remote Access
Hackers are quickly exploiting a high-severity vulnerability in VMware vCenter, using it to gain persistent remote access to affected systems, with evidence of attacks emerging just days after patches were released. This alarming timeline suggests that publicly disclosing vulnerabilities can sometimes inadvertently hand attackers a roadmap for exploitation.

Linux KVM Flaw Lets Privileged Guests Escape to Host
A newly discovered flaw in Linux KVM, dubbed "Zapscape," allows attackers with kernel privileges inside a virtual machine to break free from isolation and execute code on the host system. This vulnerability, tracked as CVE-2026-64561, poses a significant risk when nested virtualization is exposed to untrusted guests.

Broadcom Disrupts VMware with Emergency Patches for Critical Flaws
Broadcom has just released emergency security patches to tackle critical flaws in VMware's vCenter, ESX, Workstation, and Fusion - and it's urging admins to act fast, treating affected systems as immediately vulnerable. Three critical vulnerabilities, including CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, are among the five patched across these products and others that contain vCenter or ESX.

Broadcom Fixes VMware Flaws That Allow Auth Bypass and Code Execution
Broadcom has patched critical VMware vCenter flaws, including a severe authentication-bypass vulnerability that could let hackers gain unauthorized access to your system. This game-changing flaw, rated 9.8 in severity, can be exploited by malicious actors with network access to wreak havoc on your VMware environment.

OVH Disrupts Januscape Bug with Mass Reboots
To minimize risk to customers, OVH took swift action with mass reboots to disrupt the Januscape bug, opting for decisive action over detailed communication that could have tempted some to test the publicly available exploit. This critical flaw, tracked as CVE-2026-53359, allowed attackers to escape guest VMs and wreak havoc on host systems.

Linux Flaw Enables VM Escape on Intel, AMD Devices
A newly disclosed 16-year-old Linux kernel vulnerability, dubbed Januscape, allows hackers to easily escape virtual machines and compromise their host systems - all with just a few clicks from within the guest system. This shocking security flaw, tracked as CVE-2026-53359, has been lurking in the kernel for nearly two decades.

Linux KVM Flaw Lets Guest VMs Escape to Host on Intel, AMD Systems
A newly discovered 16-year-old flaw in Linux's KVM, nicknamed "Januscape," allows guest virtual machines to break free and interact with their host systems on Intel and AMD machines, potentially leading to full host code execution. This vulnerability, tracked as CVE-2026-53359, can cause a host to panic and be exploited for malicious purposes.