Massive zero-day: cyber pro breaks out of virtual machine, takes root on KVM host
An extraordinary discovery earned a modest bug bounty.

Image by Cybernews.
- Vercel confirmed a critical KVM zero-day that can let a guest virtual machine escape to the host.
- The researcher says the flaw can give attackers root-level access across cloud tenants.
- No exploit details, affected versions, CVE, or confirmed attacks have been publicly reported.
- The $50,000 bounty sparked debate over rewards for bugs that affect major cloud providers.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A huge KVM zero-day vulnerability has been discovered. A cybersecurity researcher managed to fully escape a virtual machine (VM) and gain root on host “in industry standard hypervisor.”
Vercel has confirmed that Paulos Yibelo, an independent security researcher and bug bounty hunter, has discovered a critical zero-day vulnerability affecting KVM (Kernel-based Virtual Machine), a foundational Linux virtualization technology that powers most of the cloud.
“We’ve confirmed a KVM zero day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization. 2026 is wild!” Guillermo Rauch, CEO of Vercel, posted on X.
According to Yibelo, the zero day enables an attacker on any guest VM to fully escape the VM and gain root on the host system.
The bug bounty notification says that the bug covers microVM to EC2 host escape, which leads to cross-tenants read, modify and remote code execution – essentially a complete compromise.
No further details about the actual exploit mechanism or the affected software versions have been publicly disclosed, which likely limits the immediate risks. The vulnerable code path remains unknown, and no CVE has been assigned yet. A full technical write-up is reportedly still to come.
Vercel Sandbox, the company’s isolated cloud computing environment, runs on bare-metal EC2 (Elastic Compute Cloud) hosts and relies on KVM and Firecracker, an additional open-source microVM virtualization technology.
The potential implications of the KVM zero-day exploit are massive: compromise a single service or neglected workload in the cloud, and an attacker gains complete control over the entire server and all the tenants and virtual machines running on it. However, no confirmed exploitation of the bug has been reported.
Fingers pointed at $50K bug bounty
Many cybersecurity experts immediately questioned the bug bounty sum. Yibelo was awarded $50,000, the maximum reward in the 1 million hacking challenge previously announced for Vercel Sandbox.
“Only $50k? Do they know that you can get $1M on this one in the underground?” one of the engineers, going by the alias Wendel, responded.
Another user called it a “daylight robbery.”
Cybernews previously reported that another researcher, Hyunwoo Kim, who discovered a critical KVM guest-to-host escape bug known as Januscape, was awarded $250,000 in Google's KVMCTF bug bounty program.
Even Vercel’s CTO, Malte Ubl, agrees and suggests there should be a fund that rewards researchers who find vulnerabilities that “impact everybody” – every hyperscaler, every AI lab, every company on the planet.
“This idea could genuinely transform bug bounty and really align incentives of most researchers and hackers, as well as help the internet find the nastiest bugs really quickly,” Yibelo acknowledges.
“If done, I have no doubt it would start a security revolution!”
The researcher warns that many talented hackers don’t even bother to report bugs because of the current “mess,” and many researchers go unrecognized.
“So god knows what's buried in random dependencies of the everyday tools we use,” Yibelo said.
Cybernews previously reported that the onslaught of AI-discovered Linux Kernel vulnerabilities is eroding confidence in container isolation, and VMs are seen as a stronger security boundary. The newly disclosed KVM zero-days now put that boundary to the test as well.