Docker Sandboxes security update for CVE-2026-77179 and CVE-2026-79994
Security Patch Release
Summary
Hide ▲
Show ▼
Docker released a security update for Docker Sandboxes that fixes CVE-2026-77179 and CVE-2026-79994, closing a Critical macOS host-file escape and a High Unix-socket relay flaw. The update ships in 0.42.0 for systems affected before that release. Users should upgrade to 0.42.0 or later or use clone mode if they cannot update yet.
Related Happenings
ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
H score43
First: 27.08.2026 00:33
Last: 27.08.2026 00:33
Sources 1
About this happening:
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
ThemeFusion security patch release for CVE-2026-18431
Security Patch ReleaseAbout this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
Cisco security patch release for CVE-2026-20337
Security Patch Release
H score30
First: 11.08.2026 14:03
Last: 11.08.2026 14:03
Sources 1
About this happening:
Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...
Cisco security patch release for CVE-2026-20337
Security Patch ReleaseAbout this happening: Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...
Gitea security patch release for CVE-2026-59774
Security Patch Release
H score65
First: 05.08.2026 14:04
Last: 05.08.2026 14:04
Sources 1
About this happening:
Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Gitea security patch release for CVE-2026-59774
Security Patch ReleaseAbout this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch Release
H score32
First: 27.07.2026 17:40
Last: 27.07.2026 17:40
Sources 1
About this happening:
vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch ReleaseAbout this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
NodeBB eight-flaw security patch release (4.14.2)
Security Patch Release
H score34
First: 24.07.2026 10:41
Last: 24.07.2026 10:41
Sources 1
About this happening:
NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...
NodeBB eight-flaw security patch release (4.14.2)
Security Patch ReleaseAbout this happening: NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...
Timeline
-
17.09.2026 18:37 2 articles · 13h ago
Docker 0.42.0 fixes Docker Sandboxes host-escape flaws
Mitigation Patch UpdateDocker 0.42.0 fixed CVE-2026-77179 in the virtio-fs host server and CVE-2026-79994 in the sandbox Unix domain socket relay, closing paths that could let sandboxed code escape the shared project directory, read or change host files, or reach AF_UNIX sockets outside the authorized workspace.
Show sources
- Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files — thehackernews.com — 17.09.2026 18:37
- Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files — thehackernews.com — 17.09.2026 18:37
-
15.09.2026 03:00 1 articles · 3d ago
Docker warns of macOS sandbox-escape and Unix socket relay flaws
Initial DisclosureDocker issued a security announcement for Docker Sandboxes on macOS, warning that CVE-2026-77179 could let malicious guest code escape the shared project directory and read or modify host files, with possible code execution on the host, and that CVE-2026-79994 could expose host-side AF_UNIX sockets; the CVE-2026-79994 record was corrected to 0.42.0 after initially listing 0.41.0 as the first fixed version.
Show sources
- Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files — thehackernews.com — 17.09.2026 18:37