
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65928 is a vulnerability in QEMU's DMG (Apple Disk Image) handling component involving out-of-bounds memory accesses. The CVE is currently in "Reserved" status, meaning full vulnerability details have not yet been publicly disclosed. It is estimated to be of Medium severity based on Feedly AI analysis (Feedly). The vulnerability was first detected in threat discussions around July 2026, with scanner detections appearing in August–September 2026 (Tenable).
The vulnerability is rooted in improper bounds checking within QEMU's DMG image parsing code, consistent with CWE-125 (Out-of-bounds Read) or CWE-787 (Out-of-bounds Write). A fix was committed to the QEMU upstream repository (QEMU Commit), indicating the issue was addressed at the source level. Because the CVE remains in Reserved status, the precise attack vector, affected versions, and exploitation preconditions have not been formally published (Feedly).
Out-of-bounds access vulnerabilities in hypervisor disk image handling components like QEMU's DMG parser can lead to memory corruption, potentially enabling denial of service (crash of the QEMU process) or, in more severe cases, arbitrary code execution within the host context. If exploitable from a guest VM, such vulnerabilities may pose a guest-to-host escape risk, which would have significant confidentiality, integrity, and availability implications for virtualized environments. The full impact scope remains unclear pending official disclosure (Feedly).
No public proof-of-concept exploit code has been identified for CVE-2026-65928, and there is no evidence of in-the-wild exploitation at this time (Feedly). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS score data is not yet available given the Reserved status of the CVE. Detection signatures have been added by Nessus (plugin 341602) and Qualys (detection ID 6600572), suggesting the vulnerability is considered relevant for scanning purposes (Tenable).
A fix has been committed to the QEMU upstream repository; users should update to a QEMU version that includes commit 86acc650be113d7007bbb1499a4f50bda5c6d705 or later (QEMU Commit). Debian has issued a security update addressing this issue as of September 2026 (Debian Advisory). As a general workaround, restrict the use of DMG disk image files in QEMU environments where untrusted images may be processed, and monitor vendor channels for official CVE publication and additional guidance (Feedly).
Security scanner vendors Tenable (Nessus) and Qualys have added detection plugins for this vulnerability, indicating awareness within the vulnerability management community (Tenable). Debian has issued a security advisory incorporating the fix, reflecting downstream Linux distribution response (Debian Advisory). No notable public researcher commentary or social media discussion has been identified beyond automated threat intelligence tracking.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."