SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-49744

HIGH · CVSS 7.8 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Kernel software within a Guest VM is vulnerable to improper command execution that can lead to out-of-bounds memory access on the GPU firmware, potentially allowing malware to escalate privileges and escape virtualization boundaries. This vulnerability poses a significant risk to environments utilizing virtual machines, particularly those handling sensitive data or critical operations. Organizations employing virtualization technologies should prioritize patching and mitigating this issue to safeguard against potential exploitation.

CVE
CVE-2026-49744
Severity
HIGH
CVSS
7.8
EPSS
0.11%

Original NVD Description

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.

Related CVEs

Other vulnerabilities affecting the same vendor(s)