<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Docker Sandboxes (&lt; 0.42.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/docker-sandboxes--0.42.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 13:06:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/docker-sandboxes--0.42.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in Docker Sandboxes</title><link>https://feed.craftedsignal.io/briefs/2026-09-docker-vulnerabilities/</link><pubDate>Wed, 16 Sep 2026 13:06:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-docker-vulnerabilities/</guid><description>Multiple vulnerabilities, including CVE-2026-77179 and CVE-2026-79994, in Docker Sandboxes versions prior to 0.42.0 could allow remote code execution, data confidentiality breaches, and integrity loss.</description><content:encoded><![CDATA[<p>The French National Cybersecurity Agency (ANSSI) has published an advisory regarding multiple vulnerabilities identified within Docker Sandboxes. These vulnerabilities, identified as CVE-2026-77179 and CVE-2026-79994, affect versions prior to 0.42.0. If successfully exploited, these flaws could allow a remote attacker to achieve arbitrary code execution on the host or target container, compromise the confidentiality of sensitive data, or impact the integrity of stored or processed information. Organizations utilizing Docker Sandboxes are advised to refer to the official vendor security bulletin to apply the necessary patches. Given the potential for remote code execution, timely patching is critical to mitigate the risk of unauthorized system access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities may result in full remote control over the affected containerized environment. This exposure risks the exfiltration of sensitive data, modification of application logic, and broader lateral movement within the host system. The scope of impact extends to any organization deploying Docker Sandboxes in versions earlier than 0.42.0.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Docker Sandboxes to version 0.42.0 or later immediately.</li>
<li>Review the official vendor security announcement at <a href="https://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994">https://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994</a> to verify all addressed security fixes.</li>
<li>Identify and inventory all systems running Docker Sandboxes in the environment to ensure comprehensive patching.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>docker</category></item></channel></rss>