# Traefik security bypass flaws patched

Published: 2026-07-02 · Severity: medium
Canonical: https://vorant.io/reports/81caa513-b01c-5f99-bc3e-294bb8ff531b/traefik-security-bypass-flaws-patched

> Multiple vulnerabilities in Traefik proxy versions 2.11.x, 3.6.x, and 3.7.x allow attackers to bypass security policies; patches available.

The French CERT has disclosed multiple security policy bypass vulnerabilities affecting Traefik, a popular cloud-native application proxy and load balancer. The flaws impact three branches: versions 2.11.x prior to 2.11.51, versions 3.6.x prior to 3.6.22, and versions 3.7.x prior to 3.7.6. These vulnerabilities could allow an attacker to circumvent security controls implemented within Traefik deployments.

The vendor has released patches addressing the issues, tracked as CVE-2026-54763, CVE-2026-54764, and CVE-2026-54765. Organizations running affected Traefik versions should prioritize updating to the patched releases to prevent potential security policy bypasses. Given Traefik's widespread use in containerized and microservices environments, the exposure surface for these vulnerabilities may be significant across cloud-native infrastructure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-54763, CVE-2026-54764, CVE-2026-54765

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0823

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/81caa513-b01c-5f99-bc3e-294bb8ff531b/traefik-security-bypass-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
