Windows VMSwitch CVE-2026-57092: CVSS 9.9 guest-to-host escape in Hyper-V
Microsoft's July 14 Patch Tuesday closed CVE-2026-57092 — a CVSS 9.9 use-after-free in the Windows VMSwitch that lets a low-privileged guest reach the Hyper-V host.
Microsoft's July 14 Patch Tuesday closed CVE-2026-57092 — a CVSS 9.9 use-after-free in the Windows VMSwitch that lets a low-privileged guest reach the Hyper-V host.
WordPress 7.0.2 and 6.9.5 shipped July 17 to close CVE-2026-63030 — a pre-auth RCE in Core built on the CVE-2026-60137 SQL injection. Detection PoC is already public.
Zoom bulletin ZSB-26014 patches CVE-2026-53412, a CVSS 9.8 pre-auth account takeover in Zoom Workplace and the VDI client for Windows. Update to 7.0.0 / 7.0.10 / 6.6.15 / 6.5.18.
Nightmare Eclipse published LegacyHive on GitHub the same day as Microsoft's July 2026 Patch Tuesday. It's an unpatched profsvc LPE that still works on fully-updated Windows.
A use-after-free in the Linux kernel's futex priority-inheritance path, present since May 2011, hands root to any local user. Fixed in mainline commit 3bfdc63936dd; distros started shipping July 9.
A shadow-MMU use-after-free in KVM/x86 lets a root guest reach into the host on Intel VMX and AMD SVM. Stable kernels shipped the fix on July 4; embargo lifted July 6 with a public PoC.
Researcher Massimiliano Oldani published a working root exploit (packet_edit_meme) for CVE-2026-46331 one day after the kernel.org CVE landed. Ubuntu 18.04–26.04 vulnerable.
JFrog published a full local-root exploit for the DirtyFrag-family kernel flaw CVE-2026-43503 on June 25. Patched in v7.1-rc5. Container hosts are the priority.
Exodus Intelligence published a complete local root exploit for CVE-2026-23111 — a one-character nf_tables UAF patched upstream Feb 5. Container escape on default distros.