{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adockersandboxes/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:docker:sandboxes:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-77179"},{"id":"CVE-2026-79994"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Docker Sandboxes (\u003c 0.42.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","docker"],"_cs_type":"advisory","_cs_vendors":["Docker"],"content_html":"\u003cp\u003eThe French National Cybersecurity Agency (ANSSI) has published an advisory regarding multiple vulnerabilities identified within Docker Sandboxes. These vulnerabilities, identified as CVE-2026-77179 and CVE-2026-79994, affect versions prior to 0.42.0. If successfully exploited, these flaws could allow a remote attacker to achieve arbitrary code execution on the host or target container, compromise the confidentiality of sensitive data, or impact the integrity of stored or processed information. Organizations utilizing Docker Sandboxes are advised to refer to the official vendor security bulletin to apply the necessary patches. Given the potential for remote code execution, timely patching is critical to mitigate the risk of unauthorized system access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities may result in full remote control over the affected containerized environment. This exposure risks the exfiltration of sensitive data, modification of application logic, and broader lateral movement within the host system. The scope of impact extends to any organization deploying Docker Sandboxes in versions earlier than 0.42.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Docker Sandboxes to version 0.42.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview the official vendor security announcement at \u003ca href=\"https://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994\"\u003ehttps://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994\u003c/a\u003e to verify all addressed security fixes.\u003c/li\u003e\n\u003cli\u003eIdentify and inventory all systems running Docker Sandboxes in the environment to ensure comprehensive patching.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T13:06:24Z","date_published":"2026-09-16T13:06:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-docker-vulnerabilities/","summary":"Multiple vulnerabilities, including CVE-2026-77179 and CVE-2026-79994, in Docker Sandboxes versions prior to 0.42.0 could allow remote code execution, data confidentiality breaches, and integrity loss.","title":"Multiple Vulnerabilities in Docker Sandboxes","url":"https://feed.craftedsignal.io/briefs/2026-09-docker-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:docker:sandboxes:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}