Vercel confirms KVM zero-day allowing full guest-to-host VM escape
Vercel's CEO confirmed a KVM zero-day reported via the Vercel Sandbox bounty program that reportedly lets guest code gain root on the host. No CVE or patch has been published yet.
The latest cybersecurity news in Vulnerabilities.
Vercel's CEO confirmed a KVM zero-day reported via the Vercel Sandbox bounty program that reportedly lets guest code gain root on the host. No CVE or patch has been published yet.
Fortra fixed eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical bugs that could enable authentication bypass and root-level command execution.
Admins report NetScaler ADC and Gateway devices on build 14.1-73.37 rebooting after SAML traffic crashes the nsaaad service. Citrix is preparing a new bulletin and fixed build.
GitLab has fixed CVE-2026-90970, a critical flaw in its self-hosted AI Gateway that lets authenticated Duo Agent Platform users escape a prompt template sandbox and run commands.
CISA has added two actively exploited Zammad flaws to its KEV catalog. The chain was used to breach Dutch nonprofit DIVD, and the root escalation bug reportedly remains unpatched.
Dell urges customers to upgrade Container Storage Modules to 1.18.0 after fixing critical flaws that can give unauthenticated attackers admin control over connected storage arrays.
Fortinet disclosed an actively exploited FortiMail flaw rated 9.8 that lets unauthenticated attackers write arbitrary files; CISA added it to KEV with an October 4 deadline.
Cisco warned that attackers are exploiting a critical authentication bypass in Catalyst SD-WAN Manager that grants admin access; CISA ordered federal agencies to patch by 3 October.