logo

ITScape KVM Escape: Public PoC Exploit Threatens Cloud Hosts

ID: 28d483c4-a41f-5d84-828e-d73296802da8

STIX ID: report--28d483c4-a41f-5d84-828e-d73296802da8

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Do Son

...
...

A critical KVM/arm64 vulnerability (CVE-2026-46316, dubbed ITScape) and a public proof-of-concept exploit have been disclosed; the flaw is a VGIC-ITS race condition allowing untrusted guest VMs to escape to the host and obtain kernel (root) privileges, posing severe risk to multi-tenant arm64 public clouds — maintainers have merged a patch and operators must apply it immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.