CVE-2026-34040: exploitation status and patch state
CVE-2026-34040 · CVSS 8.8 HIGH · EPSS 10%
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
Is CVE-2026-34040 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 10%.
Public exploit code: none found in monitored sources.