# Docker Sandboxes flaws enable remote code execution

Published: 2026-09-16 · Severity: routine
Canonical: https://vorant.io/reports/b8f61811-c4c5-5507-9982-ad5a50792737/docker-sandboxes-flaws-enable-remote-code-execution

> CERT-FR advisory: two vulnerabilities in Docker Sandboxes before 0.42.0 allow remote code execution and data confidentiality/integrity breaches; patches available.

CERT-FR has issued an advisory relaying a Docker security bulletin covering two vulnerabilities, CVE-2026-77179 and CVE-2026-79994, affecting Docker Sandboxes versions prior to 0.42.0. Successful exploitation could allow an attacker to achieve remote arbitrary code execution, as well as compromise the confidentiality and integrity of data handled by the affected component.

No indication of active exploitation in the wild is provided in this bulletin. Docker has published fixes in version 0.42.0 of Docker Sandboxes; defenders running this component should consult the official Docker security announcement and update affected instances to the patched version as soon as possible.

## Mentioned in this report

- Vulnerabilities: CVE-2026-77179, CVE-2026-79994

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1189

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b8f61811-c4c5-5507-9982-ad5a50792737/docker-sandboxes-flaws-enable-remote-code-execution.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
