CPython security-policy bypass patched
A security-policy bypass vulnerability in CPython has been disclosed; vendors have released patches.
CERT-FR has published an advisory for a security-policy bypass vulnerability affecting CPython, the reference implementation of the Python programming language. The flaw is tracked as CVE-2026-4360 and allows an attacker to circumvent security policies enforced by the interpreter.
The vulnerability affects CPython installations that have not applied the latest security patches. The Python Security Response Team issued a security bulletin on 30 June 2026 with remediation guidance. Organizations running Python-based applications should prioritize patching to prevent potential exploitation.
Given the widespread deployment of Python across software ecosystems—from web applications to infrastructure automation—this vulnerability represents a significant attack surface. However, the advisory provides limited technical detail on exploitation complexity or active targeting, and no proof-of-concept or in-the-wild exploitation is mentioned.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0828
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free