Stan Shaw
I’m an independent security researcher focused on vulnerability discovery in widely-deployed infrastructure: operating system kernels, hypervisors, browsers, and language runtimes.
Public findings include a guest-to-host code execution in VMware Workstation and Fusion via the VMXNET3 virtual NIC (CVE-2026-59346, reported through Trend Micro ZDI), a pre-auth remote code execution in nginx’s script engine (CVE-2026-42533), a guest-to-host escape chain in QEMU’s CXL Type 3 mailbox emulation (writeup), a guest-triggered heap out-of-bounds in KVM’s SEV-SNP page-state-change handling (CVE-2026-53360), kernel privilege escalations in the Linux DRM GEM subsystem (CVE-2026-46215) and FUSE readdir cache (CVE-2026-31694), a SQL injection in the Django ORM (CVE-2025-64459), and a use-after-free in CPython’s perf_trampoline (Issue #143228).
Additional findings in browsers and mobile baseband are under coordinated disclosure and will be published here after patches ship.
