By Aytun Çelebi
Publication Date: 2026-10-07 08:38:00
Vercel has confirmed a zero-day vulnerability in Linux KVM that security researcher Paulos Yibelo described as allowing a full virtual machine escape, CEO Guillermo Rauch said.
Yibelo said on X that the flaw could allow a user inside a guest virtual machine to gain root access on its host. He shared a screenshot showing a bug-bounty award for the discovery, which he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!”
“We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization,” Rauch wrote, identifying KVM as the hypervisor affected by Yibelo’s discovery.
No further technical details about the vulnerability have been publicly disclosed. The Register said it found no discussion on relevant mailing lists and had asked both Rauch and Yibelo for additional information.
A guest-to-host escape could allow someone controlling a guest virtual machine to take over the server hosting it. That access could potentially extend to control over other guest virtual machines running on the same server.
KVM is widely used in cloud and enterprise virtualization. AWS and Google use it to power…



