Threat reportZero-DayTL-2026-2878
Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty Awarded
Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root (TL-2026-2878) is a high-severity zero-day vulnerability, first published 2026-10-04. It has no confirmed attribution, affects KVM (Kernel-based Virtual Machine) KVM hypervisor (as stated by, maps to 4 MITRE ATT&CK techniques (T1005, T1059, T1078), and is covered by 9 detection rules and 11 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 11Indicators of compromise
Key facts for TL-2026-2878
- Threat ID
- TL-2026-2878
- Severity
- HIGH
- Status
- TRACKING
- Category
- ZERO_DAY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, cloud-services, software-development
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 11
How Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root works
Researcher Paulos Yibelo reported a KVM zero-day enabling full guest-to-host VM escape with root on the host through Vercel's Sandbox bug bounty; Vercel CEO Guillermo Rauch confirmed it and paid the $50,000 maximum. No CVE, affected versions, patch status or exploit details have been disclosed, and there is no evidence of in-the-wild exploitation.
On 2026-10-03 security researcher Paulos Yibelo announced on X a 'Full VM escape zeroday (guest>host root in industry standard hypervisors)'. Vercel CEO Guillermo Rauch confirmed on X that Vercel had 'confirmed a KVM 0day through our Vercel Sandbox bounty program', described KVM as the industry's gold-standard Linux virtualization solution, thanked Yibelo and other researchers, and said a full write-up is coming. Cyber Security News (2026-10-04) reports that Vercel awarded Yibelo $50,000, the maximum payment for a single report.
The finding came from Vercel's public HackerOne Sandbox program (open 2026-08-18 to a scheduled close of 2026-09-01, up to $1,000,000 total pool, up to $50,000 per report). Per Vercel's challenge page, every Vercel Sandbox runs in its own Firecracker microVM with a dedicated guest kernel on bare-metal EC2 hosts; the microVM, not the inner Linux container, is the security boundary. In scope were escapes from Firecracker to the EC2 host, cross-tenant read/modify/execute/crash through the compute layer, and defeating the host-side network firewall. Reports required a live proof-of-concept, so the escape was demonstrated to Vercel, but no technical details have been released.
Undisclosed as of publication: CVE identifier, CVSS, affected kernel versions, CPU vendor/architecture requirements, whether it is a Linux kernel KVM bug or lies in a different component, patch availability, and whether any customer data was exposed. This record therefore does not infer specifics. Commentators (e.g. @s1r1u5_) warned the blast radius could be large, which is opinion, not evidence.
Context, not established as related: in July 2026 a separate 16-year-old Linux KVM shadow-MMU use-after-free dubbed Januscape (CVE-2026-53359, companion CVE-2026-46113, found by Hyunwoo Kim via Google kvmCTF) was disclosed; it requires root in a guest with nested virtualization enabled and was fixed in stable kernels on 2026-07-04. Cyber Security News notes no confirmed link between Januscape and the Vercel finding, and the CSA note on Januscape does not mention Vercel. Defenders should watch for the promised Vercel write-up and any CVE assignment before treating the two as the same bug.
Defensive takeaway: guest-to-host escape on multi-tenant sandbox, CI/CD and AI-agent execution platforms breaks tenant isolation. Until details are published, prioritize hypervisor/kernel patch hygiene, restrict nested virtualization and /dev/kvm exposure where not required, monitor host-side telemetry for unexpected processes spawned by VMM (e.g. Firecracker/QEMU) processes, and subscribe to Vercel, kernel.org KVM and distro security advisories.
MITRE ATT&CK techniques used in TL-2026-2878
Collection
Execution
T1059 Command and Scripting Interpreter
Initial Access
Privilege Escalation
Affected products and versions in Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root
- KVM (Kernel-based Virtual Machine) — KVM hypervisor (as stated by Vercel/researcher; component and versions undisclosed)
- Vercel — Vercel Sandbox (Firecracker microVMs on bare-metal EC2 hosts) - platform where the bug was demonstrated
Remediation for Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root
Patches
- No patch or fixed version has been disclosed for this specific issue as of 2026-10-04
Immediate actions
- Monitor Vercel's promised technical write-up, kernel.org KVM mailing list and distribution security advisories for a CVE and fixed versions
- Inventory multi-tenant workloads that run untrusted code in KVM-based VMs or microVMs (Firecracker, QEMU/KVM, cloud sandboxes)
- Apply the latest vendor/distro kernel updates on KVM hosts as soon as fixes are published
Workarounds
- No vendor workaround published; as a general hardening step disable nested virtualization (kvm_intel.nested=0 / kvm_amd.nested=0) and restrict /dev/kvm access where not needed (guidance from the unrelated Januscape CVE-2026-53359, applicability to this bug unconfirmed)
Longer-term hardening
- Treat the hypervisor, not the container, as the tenant isolation boundary and layer host hardening (seccomp, jailer, minimal host attack surface)
- Alert on unexpected child processes, outbound connections, or file writes by VMM processes on the host
- Segment and minimize secrets on hosts that run untrusted guest code so a host escape has limited blast radius
Timeline of Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root
- Context only: fix for the unrelated Januscape KVM shadow-MMU use-after-free (CVE-2026-53359) merged into mainline Linux; no confirmed link to the Vercel finding.
- Context only: stable kernels 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177, 5.15.211 and 5.10.260 released with the Januscape fix.
- Vercel opens its public HackerOne Vercel Sandbox challenge: up to $1M total, up to $50,000 per report, scope includes Firecracker microVM escape to the EC2 host.
- Scheduled closing date of the Vercel Sandbox $1M challenge.
- Vercel CEO Guillermo Rauch confirms on X a KVM 0day found through the Vercel Sandbox bounty program and says a full write-up is coming.
- Paulos Yibelo announces on X a full VM escape zero-day (guest to host root in industry standard hypervisors).
- Cyber Security News reports the $50,000 maximum bounty; no CVE, affected versions or patch status disclosed.
Sources cited for Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root
- Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000
- Guillermo Rauch (@rauchg) on X: confirmed a KVM 0day through the Vercel Sandbox bounty program
- Vercel Confirms KVM 0day Allows Full VM Escape to Host Root
- $1 million hacker challenge for Vercel Sandbox
- Vercel Sandbox bug bounty program (HackerOne)
- This company wants you to break out of its security sandbox - and there's $1 million up for grabs (ITPro)
- Januscape: 16-Year-Old Linux KVM Flaw Lets Guest Escape to Host (The Hacker News) - related context, not confirmed linked
- CSA Research Note: Januscape KVM Guest-to-Host Escape (CVE-2026-53359) - related context
Detection coverage for TL-2026-2878
As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2878 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.