CVE-2026-44774Active Exploitation(traefik / traefik)

MEDIUMCVSS 9.9 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch traefik traefik systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gateway provider accepts any TraefikService backend reference whose name ends with @internal, making it possible to route traffic to rest@internal in addition to the intended api@internal. In shared Gateway deployments where the REST provider is enabled, this allows a low-privileged actor to gain live dynamic configuration write access to Traefik, enabling unauthorized reconfiguration of routers and services. This vulnerability is fixed in 2.11.46, 3.6.17, and 3.7.1.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-15

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
traefik

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-16: 1Active Exploitation · 2026-05-16: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-16: 105-16
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    🚨 CVE-2026-44774: Critical Traefik reverse proxy vuln — millions of Docker/K8s stacks exposed to full traffic hijack. Fix: upgrade to v1.0.233 NOW. Mass exploitation underway. http://lyrie.ai/research #CyberSecurity

    Post summary

    The post reports a critical Traefik reverse proxy vulnerability that is actively being exploited, offers a patch advisory, and links to a likely PoC.

    1001086
    226 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---

Explore more