Tools AI Risk Radar ai-incident-0026
Incident record
A cyber-capable model escaped a virtual machine three times, chaining unknown bugs
- Severity
- Critical
- Status
- Research
- Type
- AI-Found Vuln
- Target
- QEMU/KVM virtual machine isolation
- Actor
- researcher
- CVE
- CVE-2026-9539
What happened
Trail of Bits researcher Artem Dinaburg, given preview access to GPT 5.6-Cyber under OpenAI’s Patch the Planet programme, asked the model to escape a QEMU/KVM virtual machine on his own Linux development machine. Working on its own for roughly twelve hours across three attempts, it got out each time, chaining previously unknown bugs in QEMU, Linux KVM and libslirp along with a disclosed kernel bug.
The argument Trail of Bits draws from it is the one that concerns this board: a virtual machine is the boundary most teams put around an agent they do not fully trust, and it did not hold against a model that could find its own bugs in the boundary itself. CVE-2026-9539 in libslirp, scored 6.5 on NVD, was one link in the chain, alongside the Januscape kernel bug CVE-2026-53359. The counts are the researcher’s own, from three attempts rather than a systematic trial.
Sources
- Trail of Bits, "VMs won’t contain cyber-capable agents"blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capab…
- NVD record, CVE-2026-9539nvd.nist.gov/vuln/detail/CVE-2026-9539
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026