Impact
Low
CVE
CVE-2026-64531
Version(s)
4.9.0
First published
Last updated

OVSwrap

We are aware of the high profile ‘OVSwrap’ exploit which impacts the RHEL 9 kernel.

It is important to note that this exploit only impacts VQCM 4.9.0 and that it requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. The impacted kernel modules are also not loaded by default within the VQCM VM, preventing exploitation without a privileged user first having loaded these modules. 

To ensure peace of mind for our customers and meet the our high levels of security and transparency we have made available a mitigation playbook which can be applied to a running VQCM instance. This will make sure the impacted modules are not loaded and prevent them from being loaded in the future. This should not impact the running VQCM instance at all and there should be no down time.

If you have any questions about this CVE, please email security@vqcomms.com

To request access to the playbook, please email support@vqcomms.com

VQ’s Monthly News – Jul 2026

  • News

VQ Communications Secures Milestone U.S. Army Agreement for Sovereign Collaboration

  • News

VQ’s Monthly News – June 2026

  • News