Unpatched Linux KVM host kernel vulnerable to CVE-2026-53359 (Januscape)
Identifies Linux systems acting as KVM hypervisors that are running kernels vulnerable to CVE-2026-53359 (Januscape), a use-after-free vulnerability in the shadow MMU (arch/x86/kvm/mmu/mmu.c). This vulnerability permits a guest virtual machine to escape into the underlying host environment, potentially compromising the hypervisor and other hosted workloads.
Microsoft Sentinel (KQL)

