SecAlerts
D

Docker

Security Risk Profile

50
/100
medium

Security Risk Score

Comprehensive risk assessment based on 254 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 11, 2014 to present

254
Total CVEs
97
Critical+High
5
Exploited
61
Unpatched

Threat Assessment

Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
61
Critical/High
Risk Level
50/100
medium
⚠️ 5 Active Exploits⚡ 3 Zero-Days📈 3 in Last 30 Days

Severity Distribution

Critical
25
High
72
Medium
52
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
13

Age Distribution

Common Weaknesses (CWE)

1
Input Validation
10
2
Race Condition
8
3
Path Traversal
6
4
XSS
5
5
Code Injection
5

Most Affected Products

1. Docker Docker Windows104
2. Docker Docker86
3. Docker Engine74
4. Docker docker73
5. Docker Docker Desktop48

Recent Vulnerabilities

See more →
https://reddit.com/r/cybersecurity/comments/1wkei8h/cve202677179_dockers_hypervisor_for_mac/
unknown

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)

Sep 19, 2026🔧 No Patch
CVE-2026-79994
CVSS 8.7high

Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race

Sep 15, 2026🔧 No Patch
CVE-2026-77179
CVSS 9.4critical

Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback

Sep 15, 2026🔧 No Patch
https://reddit.com/r/netsec/comments/1vlkth5/copyescape_containertohost_arbitrary_file_write/
unknown

CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106)

Aug 11, 2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1vlkrp9/copyescape_containertohost_arbitrary_file_write/
unknown

CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106)

Aug 11, 2026🔧 No Patch
ZDI-26-451
unknown

Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability

Jul 23, 2026🔧 No Patch
ZDI-CAN-29308
unknown

ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability

Jul 23, 2026🔧 No Patch
CVE-2026-15793
CVSS 7.3high

Git source checkout from a bundle file could lead to command injection

Jul 21, 2026🔧 No Patch
CVE-2026-15791
CVSS 1.8low

LLB file operation can be tricked to remove /tmp directory contents

Jul 21, 2026🔧 No Patch
CVE-2026-15788
CVSS 5.6medium

WCOW cache mount source selector resolves NTFS junctions outside of cache root

Jul 20, 2026🔧 No Patch

Monitor Docker in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.