Skip to content

CVE-2026-34079

CVE

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
April 8, 2026
Last Seen
September 10, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Flatpak released version 1.16.4 on April 8, 2026, fixing four security vulnerabilities. The most critical issue, CVE-2026-34078, allows a complete sandbox escape, enabling unauthorized host file access and code execution. Two additional vulnerabilities, CVE-2026-34079 and GHSA-2fxp-43j9-pwvc, addres...

Mageia 10 has released security updates addressing critical Denial of Service vulnerabilities in libxml2 and libtiff. CVE-2026-6732 affects systems processing crafted xsd-validated documents, while CVE-2026-36849 targets large SamplesPerPixel tags in libtiff. Both vulnerabilities were disclosed on J...

Two critical vulnerabilities in Flatpak, identified as CVE-2026-34078 and CVE-2026-34079, were discovered, allowing malicious applications to access files outside their sandbox or delete arbitrary files on the host system. These vulnerabilities stem from improper path validation in sandbox-expose op...

Public Exploits

Checking GitHub for proof-of-concept code…