Arcane maintains a focused product line centered on a single namesake offering, with observed vulnerabilities clustering around OS command injection and missing authentication for critical functions. These recurrent patterns suggest exposure in command-processing or administrative-interface components; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arcane over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23944CRITICAL Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be proxied to remote environment agent | Jan 19, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-23520HIGH Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcanea | Jan 15, 2026 | 8.0 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arcane.
Media articles that mention a CVE ID that affects a product developed by Arcane — matched by CVE ID, not by vendor name.