We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization. 2026 is wild! Thankful to Paulos and other researchers helping us make the most secure sandbox for agents. Full writeup coming.
Full VM escape zeroday (guest>host root in industry standard hypervisors)! More soon

Oct 3, 2026 · 3:12 PM UTC

60
67
985
80,848
This
Replying to @rauchg
Larry Page, to his credit, repeatedly told me that AI will be superhuman at hacking about 10 years ago
3
1
31
6,210
Sort replies: Relevant Recent Liked
Replying to @rauchg
Can ye expedite it pls, eagerly await the write up
1
378
Replying to @rauchg
agent sandboxes quietly turned KVM from boring solved infra back into live attack surface. every untrusted tool call is now a stranger's code poking your hypervisor
2
4
1,966
Replying to @rauchg
the redacted line in that screenshot is the one i want to read
1
3
1,911
Replying to @rauchg
"My Agent escaped the sandbox"
3
831
Replying to @rauchg
a kvm 0day coming out of a sandbox bounty is the best argument i have seen for running one
9
1,351
Replying to @rauchg
I'm sorry but $50k is LOW for a sandbox(!) hypervisor(!!) 0-day(!!!). He's owed several times that, and paying *just* $50k will mostly push people to sell these instead.
130
Replying to @rauchg
the sandbox just became a suggestion
3
1,450
Replying to @rauchg
Paying researchers to attack the sandbox boundary directly is a sensible way to find this class of bug. Will the writeup say which hypervisor layers were affected?
2
842
Replying to @rauchg
there are a bunch of hypervisor 0days.. many more to be found!
474
Replying to @rauchg
wow, I got to learn how to do that, @PaulosYibelo you rock.
1
1,040
Replying to @rauchg
Take note on how to pay a bounty @OpenAI
3
519
Replying to @rauchg
a hypervisor 0day gets fixed for everyone at once, so every fleet that pins its stack for reproducibility just had the ground floor swapped with no version bump. log which host build each run lands on and mark the patch boundary in the run log, or a month of mystery drift turns out to be the substrate moving.
207
Replying to @rauchg
agent sandboxes are becoming production security boundaries, not just execution wrappers. the receipt should say what the guest touched and what the host exposed.
284
Replying to @rauchg
wait what
1
11
Replying to @rauchg
Thanks for supporting the researchers through the bounty program. A clear “what operators need to check and update” section alongside the writeup would be especially helpful.
2
386
Replying to @rauchg
Really good on you recognizing and motivating security researchers that do the hard work and tell you exploits worth millions! this is the way!
1
154
Replying to @rauchg
Agent sandboxes getting 0days is peak 2026. Glad Vercel's hunting these before the rest of us find out the hard way
2
243
Replying to @rauchg
A KVM 0day out of a sandbox bounty is wild. Agents running untrusted code all day are stress-testing virtualization harder than anything before them.
2
348
Replying to @rauchg
no sandbox survives the thing its built to contain forever. the writeup is the only thing that matters now
1
122
Replying to @rauchg
The bounty program just earned its keep. Waiting on that writeup.
1
496
Replying to @rauchg
agent permissions get the spotlight. the isolation underneath deserves just as much scrutiny
1
1
303
Replying to @rauchg
every agent sandbox that bet on kvm isolation just inherited a 0day. writeup can't come soon enough.
1
1
523
Replying to @rauchg
why defense-in-depth is non-negotiable: teams treat KVM microVMs as an impenetrable silver bullet. when guest-to-host escapes hit (virtio/vhost bugs), the hypervisor itself must be jailed: unprivileged user namespaces, seccomp-bpf filters, and read-only host mounts
1
611
Replying to @rauchg
bounty money well spent
1
91
Replying to @rauchg
A confirmed KVM 0day from a sandbox bounty is a serious stress test for agent isolation. If agents are going to run untrusted code at scale, this kind of research is what actually keeps the walls holding.
2
438
Replying to @rauchg
KVM 0day is serious. was the escape limited to the sandbox or did it reach the host kernel?
1
234
Replying to @rauchg
kvm had one job and it left the building.
1
92
Replying to @rauchg
KVM 0day through a sandbox bounty is wild 2026 really is the year of the VM escape
1
229
Replying to @rauchg
A VM escape at this layer is a useful reminder that sandbox claims need independent testing, clear boundaries and fast disclosure. Looking forward to the write-up.
64
Replying to @rauchg
You guys are awesome!
4
100
Replying to @rauchg
Time to rethink
Replying to @S1r1u5_
May I suggest you get acquainted with
116
Replying to @rauchg
kvm 0day via the agent sandbox bounty stay close to that writeup if you host agent workloads
1
2
332
Replying to @rauchg
i was promised a sandbox, not an escape room for agents
1
151
Replying to @rauchg
kernel bugs are just a vercel recruiting pipeline now
3
403
Replying to @rauchg
Nothing says "secure sandbox for agents" like finding a full VM escape in the substrate.
2
274