Critical Docker Vulnerabilities Affect Multiple Ubuntu Releases
Article Content
- •Two critical vulnerabilities in Docker's BuildKit affect multiple Ubuntu LTS versions.
- •CVE-2026-33747 and CVE-2026-33748 allow unauthorized file access and manipulation.
- •Users must update Docker to the latest versions and restart the service to mitigate risks.
Two critical vulnerabilities were discovered in Docker's BuildKit affecting Ubuntu 26.04 LTS and earlier versions. CVE-2026-33747 allows attackers to write files outside the intended state directory, while CVE-2026-33748 permits access to files outside the checked-out repository root. These vulnerabilities impact multiple Ubuntu releases including 26.04, 24.04, 22.04, and 20.04 LTS. Users are advised to update their systems to the latest package versions to mitigate these risks. The vulnerabilities were published on March 27, 2026, and are currently being addressed through system updates. Affected users must restart Docker after applying updates to ensure all changes take effect.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2026-33747 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…