
One Kernel Patch Will Not Close This VM Escape
CVE-2026-53359, named Januscape, is a 16-year-old flaw that lets a rented virtual machine break out and seize the physical host it shares with other tenants. Closing it needs two separate patches, not one, and patched Linux kernels only shipped on 4 July.










