A Linux KVM flaw on ARM64 can expose host kernel memory to guests and enable guest-to-host escape when nested virtualization is enabled.
SharePoint CVE-2026-65660 enables authenticated RCE; Microsoft patched it on August 11, and no in-the-wild exploitation is reported.