Docker Sandboxes flaws enable remote code execution
CERT-FR advisory: two vulnerabilities in Docker Sandboxes before 0.42.0 allow remote code execution and data confidentiality/integrity breaches; patches available.
CERT-FR has issued an advisory relaying a Docker security bulletin covering two vulnerabilities, CVE-2026-77179 and CVE-2026-79994, affecting Docker Sandboxes versions prior to 0.42.0. Successful exploitation could allow an attacker to achieve remote arbitrary code execution, as well as compromise the confidentiality and integrity of data handled by the affected component.
No indication of active exploitation in the wild is provided in this bulletin. Docker has published fixes in version 0.42.0 of Docker Sandboxes; defenders running this component should consult the official Docker security announcement and update affected instances to the patched version as soon as possible.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1189
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free