
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
Researcher Hyunwoo Kim documented Zapscape, CVE-2026-64561, a KVM/x86 shadow memory flaw allowing privileged L1 guest code to escape to the

Researcher Hyunwoo Kim documented Zapscape, CVE-2026-64561, a KVM/x86 shadow memory flaw allowing privileged L1 guest code to escape to the

Researcher Malcolm Stagg’s NatJack technique hijacks TCP sessions and spoofs DNS through NAT table manipulation, affecting Windows Hyper-V and Linux

Novee Security found flaws in Claude Code and Google Gemini CLI that let an attacker-controlled GitHub issue reach CI workflow

PortSwigger’s AI-assisted HTTP Terminator found roughly 30,000 HTTP desync vectors and a live Apache Traffic Server zero-day affecting roughly 700

CISA added JetBrains TeamCity CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, citing unauthenticated remote code execution in the wild.

Stealth researchers disclosed CoreBreak flaws in AWS Bedrock, Google ADK, and Vercel harnesses that let attackers invoke agent tools without

Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in

CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled

cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.

Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.