OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93834

HIGH · CVSS 8.8 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in QEMU's 9pfs subsystem allows a malicious guest user to exploit a race condition between threads, enabling them to craft a fid path that bypasses directory traversal restrictions. This can result in arbitrary file read/write access on the host and potential code execution, posing a significant risk of VM escape. Organizations using QEMU for virtualization should prioritize patching this vulnerability to mitigate the associated security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93834
Severity
HIGH
CVSS
8.8
EPSS
0.38%

Original NVD Description

A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.