HIGH 7.0 Featured FEATURED PoC
CVE-2026-53359
a.k.a. Januscape
Januscape: KVM/x86 guest-to-host escape (Intel + AMD) — kvmCTF 0-day
Use-after-free in KVM/x86 shadow MMU emulation. Lets a guest VM escape to the host via guest-side actions alone, corrupting the host kernel's shadow page tables. First public guest-to-host exploit confirmed on both Intel and AMD. Successfully used as a 0-day in Google kvmCTF. Threatens multi-tenant x86 clouds (GCP, AWS) running untrusted guests with nested virtualisation exposed.
Affected Products
- KVM/x86 (Intel + AMD)
- Multi-tenant x86 cloud hosts
References
- https://github.com/V4bel/Januscape
- https://www.openwall.com/lists/oss-security/2026/07/06/7
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-53359
This high severity vulnerability with a CVSS score of 7.0 was published on 2026-07-06 via Featured. 🚨 A public proof-of-concept exploit is available on GitHub. Affected: KVM/x86 (Intel + AMD), Multi-tenant x86 cloud hosts.
vulnfeed aggregates 14357 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.