CVE-2025-9074Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled, and with or without the "Expose daemon on tcp://localhost:2375 without TLS" option enabled. This can lead to execution of a wide range of privileged commands to the engine API, including controlling other containers, creating new ones, managing images etc. In some circumstances (e.g. Docker Desktop for Windows with WSL backend) it also allows mounting the host drive with the same privileges as the user running Docker Desktop.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-23); latest day: 2
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-10: 1Mentions · 2026-03-14: 1Mentions · 2026-05-23: 2Mentions · 2026-05-25: 1Mentions · 2026-08-11: 2PoC Mentioned / Linked · 2026-03-14: 1PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-25: 1Patch / Workaround · 2026-03-14: 1Technical Details · 2026-02-10: 1Technical Details · 2026-03-14: 1Technical Details · 2026-05-23: 2Technical Details · 2026-05-25: 1Technical Details · 2026-08-11: 202-1003-1405-2305-2508-11
Signal classification4 categories
Disclosure
342.9%
PoC
228.6%
Patch
114.3%
General
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-03-141
Patch1
2026-05-232
Disclosure1PoC1
2026-05-251
PoC1
2026-08-112
Disclosure1General1
Full discourse7 posts
  • 0xdf@0xdf_
    Disclosure

    MonitorsFour from @hackthebox_eu features PHP type juggling to dump users, CVE-2025-24367 for RCE in Cacti, and CVE-2025-9074 to abuse the Docker Desktop API and mount the Windows host drive for root. Beyond Root: a shell on Windows." https://0xdf.gitlab.io/2026/05/23/htb-monitorsfour.html

    Post summary

    The blog post announces discovery and demonstration of three CVEs (Cacti RCE and Docker Desktop API abuse) via PHP type juggling, but does not provide exploits, patches, or evidence of active exploitation.

    312164234.9K
    26.6K followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    CVE-2025-9074 in Docker Desktop <4.44.3 lets malicious containers access the Engine API unauthenticated, enabling host file access & escape. https://redsecuretech.co.uk/blog/post/docker-desktop-container-escape-via-unauthenticated-api/902 #Cybersecurity #DockerDesktop #DockerSecurity #Vulnerability #ThreatIntel #DevSecOps #Exploit #PatchNow https://t.co/cihEgQYBmt

    Post summary

    The tweet announces that CVE‑2025‑9074 in Docker Desktop <4.44.3 permits unauthenticated API access from malicious containers, potentially leading to host file access and escape.

    0101055
    41 followersView on X
  • Tao Idr@tao_idr
    Disclosure

    It gets worse: CVE-2025-9074 (CVSS 9.3) in Docker Desktop allowed containers to reach the Docker Engine API without authentication and escape to the host, with ZERO socket mount required. Unpatched daemons leave the front door wide open.

    Post summary

    The post discloses CVE-2025-9074 in Docker Desktop, describing its high‑severity (CVSS 9.3) flaw that lets containers reach the Docker Engine API without authentication and escape to the host, but it does not mention any PoC, exploit code, active attacks, or remediation.

    1000033
    157 followersView on X
  • sckull@sckull_
    PoC

    HackTheBox - MonitorsFour 🔍 API expone credenciales 💥 Cacti -&gt; Password spraying + RCE 🐳 CVE-2025-9074 https://sckull.github.io/posts/monitorsfour/

    Post summary

    A post on HackTheBox outlines the discovery of CVE-2025-9074, noting that API credentials can be exposed, enabling password spraying and remote code execution, and provides a link to the author’s detailed write‑up.

    00010542
    178 followersView on X
  • Tao Idr@tao_idr
    General

    Sources &amp; References: • Shodan / Censys research • CVE-2025-9074 (NVD, CVSS 9.3) • Trend Micro &amp; Intezer research (Graboid, Kinsing, TeamTNT) #DockerSecurity #ContainerSecurity #CloudSecurity #DevSecOps #PenetrationTesting

    Post summary

    The post lists a high‑severity vulnerability (CVE‑2025‑9074, CVSS 9.3) and research sources, but provides no evidence of PoC, exploit tools, active exploitation, or patch information.

    0000037
    157 followersView on X
  • Waqar Naeem@codewithpike
    PoC

    This was actually an easier box which was based on two CVES. One was Cacti rev shell CVE-2025-24367, while the other one was to escape the docker into host CVE-2025-9074. Learned how to escape docker and how to pragmatically use publicly available poc's. https://labs.hackthebox.com/achievement/machine/3238627/814

    Post summary

    The post notes that the author leveraged publicly available PoCs to exploit a Cacti reverse shell and Docker host escape CVEs as part of an easier Hack The Box box, focusing on how to use these PoCs rather than providing new exploit code or reporting live attacks.

    00000197
    58 followersView on X
  • Byron Warner@ScanSafeGuard
    Patch

    Heads up Docker users — CVE-2025-9074 is a nasty one. Containers can reach the Engine API without auth and escape to the host. CVSS 9.3, PoC is already out there. If you're on Desktop 4.25–4.44.2, update to 4.44.3 ASAP. #DockerSecurity #InfoSec

    Post summary

    CVE-2025-9074 lets unauthenticated containers access the Docker Engine API and escape to the host; a PoC exists and a patch (Desktop 4.44.3) is available for affected versions.

    000001
    1 followersView on X

Explore more