Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Major Security Flaws in Docker Sandboxes Patched

Major Security Flaws in Docker Sandboxes Patched

Posted on September 17, 2026 By CWS

In a significant security update, Docker has addressed two major vulnerabilities within its Sandbox environments, preventing potential exploitation by malicious guests. These vulnerabilities, identified as CVE-2026-77179 and CVE-2026-79994, could have allowed unauthorized access to sensitive host resources.

Details of the Vulnerabilities

The recent release of Docker Sandboxes version 0.42.0 on September 7 marked the resolution of these critical security issues. Docker Sandboxes typically operate using isolated microVMs, designed to run untrusted workloads safely by maintaining a strict separation between guest environments and host resources.

The primary flaw, CVE-2026-77179, is deemed critical and was present in versions 0.28.0 up to those preceding 0.42.0 on macOS. This vulnerability arose from unsafe handling within the virtio-fs host server, which manages file-sharing between sandbox guests and the host system.

Impact and Exploitation Risks

The flaw allowed attackers to exploit symbolic links in file paths, potentially redirecting file operations outside the approved workspace. This race condition could enable unauthorized access to host files, posing risks of code execution and system compromise.

The second vulnerability, CVE-2026-79994, rated as high risk, affected versions from 0.37.0 to those before 0.42.0. It involved the guest-to-host Unix domain socket relay, where a mishandling of path verification could lead to unauthorized socket connections.

This time-of-check to time-of-use vulnerability allowed attackers to manipulate socket path connections, risking exposure of sensitive data or functions.

Recommendations and Future Outlook

Organizations utilizing Docker Sandboxes are urged to update to version 0.42.0 or newer immediately, especially those on macOS executing untrusted code. Docker advises using clone mode and avoiding read-write host mounts as interim precautions if an immediate update isn’t feasible.

These disclosures underscore the necessity for timely updates and reducing host filesystem exposure in container-based workflows. Previous fixes in 2026, such as CVE-2026-17106, further illustrate this critical practice.

Maintaining up-to-date security measures and minimizing vulnerabilities is crucial for protecting technological infrastructures against potential threats.

Cyber Security News Tags:CVE-2026-77179, CVE-2026-79994, Cybersecurity, Docker, macOS, microVM, Patch, Safety, Sandbox, Security, Software, software vulnerabilities, Technology, Update, Vulnerabilities

Post navigation

Previous Post: Ransomware Threats Escalate in Manufacturing Industry
Next Post: Gyazo Security Breach: 23.62 Million Users Affected

Related Posts

New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access Cyber Security News
Anthropic Alleges Alibaba’s Unauthorized Access to AI Models Anthropic Alleges Alibaba’s Unauthorized Access to AI Models Cyber Security News
Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens Cyber Security News
China-Linked Silver Dragon Uses Google Drive in Cyberattacks China-Linked Silver Dragon Uses Google Drive in Cyberattacks Cyber Security News
Cybersecurity News Weekly Newsletter – Android and Cisco 0-Day, Teams Flaws, HackedGPT, and Whisper Leak Cybersecurity News Weekly Newsletter – Android and Cisco 0-Day, Teams Flaws, HackedGPT, and Whisper Leak Cyber Security News
New Android Malware ‘Fantasy Hub’ Intercepts SMS Messages, Contacts and Call Logs New Android Malware ‘Fantasy Hub’ Intercepts SMS Messages, Contacts and Call Logs Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service
  • CISA Recommends Cyber Decoys to Detect Hackers
  • Critical Vulnerabilities Patched by Top Cybersecurity Firms
  • AI-Assisted Malware Targets npm Users with PhantomRaven

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service
  • CISA Recommends Cyber Decoys to Detect Hackers
  • Critical Vulnerabilities Patched by Top Cybersecurity Firms
  • AI-Assisted Malware Targets npm Users with PhantomRaven

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark