A public disclosure detailed Zapscape, tracked as CVE-2026-64561, a guest-to-host escape vulnerability in KVM/x86 caused by a use-after-free in shadow MMU emulation. The flaw occurs in the recursive shadow-page "zap" path and can be triggered through guest-side actions alone, allowing corruption of host kernel shadow pages and breaking guest-host isolation. The issue affects both Intel and AMD hosts; on Intel, exploitation requires that EPT page walk lengths 4 and 5 are both exposed to the L1 guest, while no equivalent constraint was noted for AMD.
The disclosure warns that systems running untrusted guests with nested virtualization enabled are at particular risk, including multi-tenant x86 public cloud environments. Hyunwoo Kim reported the bug to the Linux kernel security team, and the issue has been patched in mainline Linux. The affected range spans from commit f95eec9bed76 through 2abd5287f083, covering code introduced in 2020 and remaining exposed until the July 2026 fix referenced on kernel.org.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Hyunwoo Kim publicly disclosed Zapscape, tracked as CVE-2026-64561, on the oss-sec mailing list after the linux-distros embargo expired. The disclosure described a use-after-free in KVM/x86 shadow MMU emulation that can enable guest-to-host escape and noted that mainline Linux had been patched.
A fix for the KVM/x86 guest-to-host escape tracked as CVE-2026-64561 was committed in mainline Linux as commit 2abd5287f083. The disclosure identifies this commit as the patch and as the end of the affected code range.
The affected code range for CVE-2026-64561 begins with commit f95eec9bed76, marking the introduction of the vulnerable KVM/x86 shadow MMU behavior later disclosed as Zapscape.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.