HIGH 7.0 Featured FEATURED PoC

CVE-2026-53359

a.k.a. Januscape

Januscape: KVM/x86 guest-to-host escape (Intel + AMD) — kvmCTF 0-day

Use-after-free in KVM/x86 shadow MMU emulation. Lets a guest VM escape to the host via guest-side actions alone, corrupting the host kernel's shadow page tables. First public guest-to-host exploit confirmed on both Intel and AMD. Successfully used as a 0-day in Google kvmCTF. Threatens multi-tenant x86 clouds (GCP, AWS) running untrusted guests with nested virtualisation exposed.

Affected Products

References

Published: 2026-07-06 · Source: Featured · Feed updated: 2026-09-18
This high severity vulnerability with a CVSS score of 7.0 was published on 2026-07-06 via Featured. 🚨 A public proof-of-concept exploit is available on GitHub. Affected: KVM/x86 (Intel + AMD), Multi-tenant x86 cloud hosts.
vulnfeed aggregates 14357 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.