Find notable cyber news and cases, enriched with sources, timelines, and signals.

Docker Sandboxes security update for CVE-2026-77179 and CVE-2026-79994

Security Patch Release
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Docker released a security update for Docker Sandboxes that fixes CVE-2026-77179 and CVE-2026-79994, closing a Critical macOS host-file escape and a High Unix-socket relay flaw. The update ships in 0.42.0 for systems affected before that release. Users should upgrade to 0.42.0 or later or use clone mode if they cannot update yet.

Related Happenings

ThemeFusion security patch release for CVE-2026-18431

Security Patch Release
H score43 First: 27.08.2026 00:33 Last: 27.08.2026 00:33 Sources 1

About this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...

Cisco security patch release for CVE-2026-20337

Security Patch Release
H score30 First: 11.08.2026 14:03 Last: 11.08.2026 14:03 Sources 1

About this happening: Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...

Gitea security patch release for CVE-2026-59774

Security Patch Release
H score65 First: 05.08.2026 14:04 Last: 05.08.2026 14:04 Sources 1

About this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...

VBulletin 6.2.2 security patch release for template-engine flaw

Security Patch Release
H score32 First: 27.07.2026 17:40 Last: 27.07.2026 17:40 Sources 1

About this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...

NodeBB eight-flaw security patch release (4.14.2)

Security Patch Release
H score34 First: 24.07.2026 10:41 Last: 24.07.2026 10:41 Sources 1

About this happening: NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...

Timeline

  1. 17.09.2026 18:37 2 articles · 13h ago

    Docker 0.42.0 fixes Docker Sandboxes host-escape flaws

    Mitigation Patch Update

    Docker 0.42.0 fixed CVE-2026-77179 in the virtio-fs host server and CVE-2026-79994 in the sandbox Unix domain socket relay, closing paths that could let sandboxed code escape the shared project directory, read or change host files, or reach AF_UNIX sockets outside the authorized workspace.

    Show sources
  2. 15.09.2026 03:00 1 articles · 3d ago

    Docker warns of macOS sandbox-escape and Unix socket relay flaws

    Initial Disclosure

    Docker issued a security announcement for Docker Sandboxes on macOS, warning that CVE-2026-77179 could let malicious guest code escape the shared project directory and read or modify host files, with possible code execution on the host, and that CVE-2026-79994 could expose host-side AF_UNIX sockets; the CVE-2026-79994 record was corrected to 0.42.0 after initially listing 0.41.0 as the first fixed version.

    Show sources