By Nadia Dubois
Publication Date: 2026-10-04 03:21:00
Vercel confirmed on October 3, 2026, that it had verified a KVM zero-day vulnerability allowing a guest virtual machine to break out and seize root access on the host, a flaw the company’s own CEO called a hit against “the industry’s gold standard solution for Linux virtualization.” The report came through Vercel’s Sandbox bug bounty program, submitted by independent security researcher Paulos Yibelo, who described it publicly as a “full VM escape zeroday.” Vercel paid out $50,000, reportedly the maximum single-report payout under that program, and said a full technical write-up is still coming.
![Vercel KVM Zero-Day: $50K Bounty, No CVE Yet [2026] Vercel KVM Zero-Day: $50K Bounty, No CVE Yet [2026]](https://i3.wp.com/tech-insider.org/wp-content/uploads/2026/10/vercel-kvm-zero-day-vm-escape-sandbox-2026-1.webp?ssl=1)


