What happened in August 2026
Between 28 and 30 August 2026 the address block of Softaculous's update servers was announced without authorisation by another network (a BGP hijack). For some hours part of the traffic to Virtualizor's update servers reached an attacker's server, which delivered a malicious update to a limited number of installations. Virtualizor explains it in its own statement; it was discussed on LowEndTalk and covered by SecurityWeek.
If you run Virtualizor, follow the statement's steps first: check for the java-jre-update service, rotate API keys, audit SSH keys and users on your servers, run the official scan script.
How KoaVM handles updates
- Every version is signed with an ed25519 key: the panel installs an update only if the signature matches, even if the file comes from the wrong server.
- Updates start when you ask from the panel (What's new › Update), not on their own.
- The previous version stays on the server (
koavm.prev): rolling back is one command.
Moving from Virtualizor to KoaVM
- In Migration › Connect a source pick Virtualizor and add the nodes (SSH access with the panel's key).
- With the Virtualizor API, KoaVM reads hostname, IP and customer of each VM and, after the move, suspends it in the old panel.
- Scan, pick customer and node, pre-flight checks on space, network, IPs and access.
- Near-live move (about 10 seconds of downtime) or cold, now or at a set time.
If anything goes wrong the source VM starts again as it was. Virtualizor import is ready in the panel; we're testing it on a lab installation as we did with SolusVM 2 and Proxmox. If you want to be among the first to migrate, write to us: we do the migration together for the first 20 providers.
Virtualizor and KoaVM side by side
| Virtualizor | KoaVM | |
|---|---|---|
| Virtualisation | KVM, Xen, OpenVZ, LXC and others | Incus (KVM VMs) on ZFS, LVM, dir, btrfs |
| Price | per-server licence, several tiers | €9 per node per month, unlimited VPSs, locked for 24 months |
| Updates | from Softaculous's servers | ed25519-signed, installed when you ask |
| Billing | WHMCS and others | WHMCS module, Koabilling, public API |
KoaVM also has inbound migration from SolusVM 1 and 2, Virtualizor, Proxmox VE and KVM/libvirt with the same IP and MAC, provider IPs via API (OVHcloud and Hetzner; Contabo and Scaleway in development) and a panel in English and Italian.
Prices exclude VAT, as of September 2026. Details on the Pricing page.
Where to start
The migration guide explains what you need and how long it takes. Then join the waitlist: the free trial includes 1 node and 5 VPSs.