Incus
CVE-2026-81494
From project-boundary escape to root command execution
A critical trust-boundary vulnerability chained with arbitrary host-file overwrite to demonstrate root command execution.
Zero-day discovery and responsible disclosure, with public reporter credit in the upstream advisory.