Unboxing BusyBox - 14 new vulnerabilities uncovered by Claroty and JFrog | JFrog

Unboxing BusyBox – 14 new vulnerabilities uncovered by Claroty and JFrog

  Update April 2026 – BusyBox is now at version 1.37.0. We recommend upgrading to 1.37.0 or later (the post originally recommended 1.34.0). Since this research was published, additional awk-related vulnerabilities have been found: CVE-2023-42365 and CVE-2023-42366, both in version 1.36.1. A separate tar vulnerability (CVE-2025-46394) was disclosed in April 2025. Notably, SUSE was still … Continue reading Unboxing BusyBox – 14 new vulnerabilities uncovered by Claroty and JFrog