Kernel KVM bug enables guest-triggered use-after-free affecting widespread virtualization hosts; high-impact guest-to-host escape/DoS risk across organizations.
CVE-2026-80726
KVM x86/mmu use-after-free allowing guest-triggered host crash or possible host compromise
Is CVE-2026-80726 being exploited?
Not confirmed. CVE-2026-80726 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.18% probability of exploitation in the next 30 days.
How severe is CVE-2026-80726?
CVE-2026-80726 is rated Critical with a CVSS score of 9.3. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-80726?
Yes. A fix has been recorded for CVE-2026-80726. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-80726 affect?
CVE-2026-80726 affects Linux kernel (KVM x86/mmu), KVM/QEMU hosts, Virtual machine guests (attack vector). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-80726?
Apply kernel/KVM patches and reboot virtualization hosts immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Guest-triggered use-after-free in KVM MMU can crash host or enable kernel RCE / guest-to-host escape.
Immediate action required
- affected>= a770f6f28b1a9287189f3dc8333eb694d9a2f0ab and < 9b7984692c18b22d6d61af3f53887fca7fddb0f1
- affected>= a770f6f28b1a9287189f3dc8333eb694d9a2f0ab and < f33ecb89d352348ed5e625f6747ac51ede254e1b
- affected>= a770f6f28b1a9287189f3dc8333eb694d9a2f0ab and < 0af4711862c5b818204d40b21f0859ad51c230e9
- affected>= a770f6f28b1a9287189f3dc8333eb694d9a2f0ab and < 66bc868a33cf1de43f22a94acd8857e0fe33393f
- affected>= a770f6f28b1a9287189f3dc8333eb694d9a2f0ab and < 9f7760a2e962cbda0d096a27d394d14ad4d22928
- affected>= a770f6f28b1a9287189f3dc8333eb694d9a2f0ab and < 5ec42d57655c690234c14aece6dd3f209778c1d8
- affected2.6.30
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.