Generic cybersecurity/ hacking image - SDx crop
– Getty Images

A long-dormant virtualization vulnerability was discovered that can expose AMD and Intel hosts to compromised virtual machines (VMs).

Dubbed Januscape, the flaw affects memory-translation code in Linux kernel-based virtual machine (KVM) hypervisors, allowing a compromised VM to reach into the host system beneath it.

According to security researcher Hyunwoo Kim, Januscape represents the first KVM exploit that can be triggered on x86-based systems. Kim added that an attacker can compromise the host running their VM solely using “guest-side” actions enacted inside the VM rather than from the host server. It does this by manipulating KVM’s shadow memory management unit (MMU) so its memory-tracking records no longer match the real object they are supposed to point to.

KVM can later delete one of those memory-tracking structures, but still accidentally keep a reference to it. This can corrupt the host kernel as the host server may later try to use memory it has already cleared away, leading it to crash. This would then see a VM “escape” to bring down the physical server and other VMs running on it.

“An attacker who has rented just a single instance on a public cloud could panic the host kernel to take down every other tenant virtual machine on the same physical machine (DoS), or run code with root privilege on the host to take over the host and all the guests on it (RCE),” Kim claimed.

The researcher added that the vulnerability lay dormant for around 16 years. Tracked as CVE-2026-53359, the issue has now been patched.

Intel and AMD systems are at risk due to their x86 architecture, with Arm64-based KVM hosts not affected.

A similar AMD/Intel issue in the virtualization realm was seen last year with the VMScape bug, which similarly allowed actors to break out of their cloud-hosted VM and expose secrets in the host machine's hypervisor without any alterations to its default configuration.

Discovered in October and described as the first of its kind, the vulnerability affected processors by circumventing the virtualization layer in a cloud setup.

Flaws in VM giant platform VMware have also been cited, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warning of “significant risks to the federal enterprise" from a vulnerability in the software’s centralized management utility.

It was also discovered last year that various bugs in VMware ESXi and vCenter servers were being exploited by a Chinese cyberespionage campaign. Dubbed "Fire Ant," the campaign also affected F5 load balancers, with the actors compromising network appliances for unauthenticated remote access and remote code execution.