CVE-2025-23266Disclosure

MEDIUMCVSS 9.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-10); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-28: 1Mentions · 2026-07-10: 2Mentions · 2026-07-14: 1Mentions · 2026-09-04: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-09-04: 1Active Exploitation · 2026-07-10: 2Patch / Workaround · 2026-09-04: 1Technical Details · 2026-03-28: 1Technical Details · 2026-07-10: 2Technical Details · 2026-07-14: 1Technical Details · 2026-09-04: 103-2807-1007-1409-04
Signal classification3 categories
Disclosure
240.0%
Active Exploitation
240.0%
PoC
120.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-281
Disclosure1
2026-07-102
Active Exploitation2
2026-07-141
PoC1
2026-09-041
Disclosure1
Full discourse5 posts
  • felipehuici@felipehuici
    Active Exploitation

    If you're running critical or multi-tenant workloads on containers, you're playing with fire. The CVE record keeps proving it: - CVE-2024-21626 — Leaky Vessels: runc container escape, host filesystem access - CVE-2025-23266 — NVIDIAScape: CVSS 9.0, triggered by a 3-line Dockerfile - CVE-2025-52881 — runc procfs write-redirect: full breakout, actively exploited in the wild by mid-2026 - CVE-2025-38617 — Linux kernel packet-socket: full container escape via user namespaces This is not a 2024 phenomenon that someone will eventually fix. The November-2025 runc trio (CVE-2025-31133 / -52565 / -52881) moved from disclosure to confirmed in-the-wild exploitation, affecting Docker, containerd and every major managed Kubernetes service. Escapes never stopped — 2024-2025 brought a fresh surge, and by 2026 the worst of them are being exploited for real. Containers don't contain. ⚠️ 📄 Full blog post: https://unikraft.com/blog/the-mighty-microvm

    Post summary

    The post lists several container escape CVEs and asserts that they are actively exploited in the wild, highlighting ongoing risks for containerized workloads.

    00066569
    909 followersView on X
  • Harsh Sharma@harsh_5harma
    Disclosure

    A 3-line NVIDIA container escape(CVE-2025-23266) could turn a malicious container into host-level compromise because privileged hooks shared the host kernel context Solution: with hypervisor-level isolation, that exploit stays inside the guest. https://t.co/GS5uTa3OOd

    Post summary

    The post announces CVE-2025-23266, a container‑escape vulnerability that can lead to host compromise, and recommends hypervisor‑level isolation as a mitigation.

    0002074
    633 followersView on X
  • Luca@lucavauda
    PoC

    I honestly forgot what a pleasure was to write a blogpost about things you learn. What does security actually look like for GPUs? I reproduced a 9.0 severity NVIDIAScape-class escape (CVE-2025-23266) from first principles, no GPU, entirely in a VM on my laptop.

    Post summary

    The author demonstrates a 9.0 severity NVIDIA Escape vulnerability (CVE-2025-23266) by reproducing it entirely in a virtual machine, effectively sharing a proof‑of‑concept of the flaw.

    1000035
    147 followersView on X
  • Jérôme Jaggi@JeromeJaggi
    Active Exploitation

    Can someone explain to me why people still trust containers? - CVE-2024-21626 (Leaky Vessels) - CVE-2025-23266 (NVIDIAScape, CVSS 9.0, a 3-line Dockerfile) - CVE-2025-52881 (runc procfs write-redirect, actively exploited in the wild by mid-2026). Those are some prominent examples but there are lots more and they are recurring, publicly disclosed vulnerabilities affecting Docker, containerd, and every major managed Kubernetes service. Also, the trend from 2024 to 2026 is not improving 😅 Containers are great for packaging and distribution - but the problem is still that a shared-kernel container was never architected to be a hard, multi-tenant security boundary, and the CVE record keeps proving it. Long live the microVM 🎉 🔗 Read the full blog post here: https://unikraft.com/blog/the-mighty-microvm

    Post summary

    The post lists several publicly disclosed container‑related CVEs, notes that CVE‑2025‑52881 has been actively exploited in the wild, and emphasizes that container security issues are persistent without citing patches or PoCs.

    0001040
    15 followersView on X
  • barrack@barrackai
    Disclosure

    GPUHammer is not the only GPU hardware vulnerability: LeftoverLocals (CVE-2023-4969): AMD, Apple, Qualcomm GPUs leak memory between processes. 181MB leaked from a single LLM query. NVBleed: cross-VM data leakage through NVLink on Google Cloud. 97.8% application fingerprinting accuracy. NVIDIAScape (CVE-2025-23266, CVSS 9.0): container escape to full root access via 3-line Dockerfile. #NVIDIA #CloudGPU

    Post summary

    The post discloses several GPU hardware vulnerabilities, providing technical details such as memory leaks and a container escape flaw, but does not supply PoC code, exploit scripts, or patch information.

    10000118
    4 followersView on X

Explore more