Kubernetes fixed CVE-2026-2270 on September 23. The StatefulSet controller bug let a user confined to one namespace get a pod created in another. Shared clusters need the upgrade and a review of cluster-wide controllers that copy fields from objects tenants can write.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
EU Cyber Resilience Act rules have required 24-hour ENISA warnings on exploited flaws in commercial container images since Sept. 11, 2026. Vendors of supported Kubernetes operators and Helm charts are on the same clock, well before the rest of the law is enforced in December 2027.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
ThreatDown says the Carbonato worm breaks into Docker daemons open on port 2375 and installs the open-source Hermes AI agent, then rescans nearby networks every five minutes to spread. An operator drives each infected host over Telegram.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence50
CARBONATO, a Docker botnet running since October 2024, hijacks hosts on open port 2375 and steals keys from 14 AI providers to fund its own LLM gateway. ThreatDown found the crew's own container registry exposed, handing defenders 4.3 GB of its toolchain.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 57%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence60
The kernel fixed CVE-2026-80521 on August 6. Ubuntu has shipped nothing for 22.04, 24.04 or 26.04, including its AWS, Azure and GCP kernels, and DepthFirst's exploit for 26.04 went public on September 22.
Publishers:linuxjournal.com · thehackernews.com Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence68
Two 2026 writeups measured Docker's alpine cold start at 0.31 and 1.23 seconds, a fourfold spread on the same test. The rootless networking backend a host runs moves throughput from about 40 Gbps to 3.
Reality
- Evidence40
- Adoption38
- Hype gap+12
- Incentives
- Insufficient
- Confidence45
Engine 29.8.0's --umask flag sets one mask for the main process, execs and healthchecks. A side-by-side test on a second daemon also shows it accepting a four-digit value and applying only the last three.
Reality
- Evidence66
- Adoption25
- Hype gap+8
- Incentives22
- Confidence58
CISA has confirmed exploitation of three Linux kernel flaws without publishing how, and the three entries do not triage the same way, because Red Hat's interim advice covers kTLS and ebtables but not the AF_ALG race.
Reality
- Evidence58
- Adoption35
- Hype gap+12
- Incentives45
- Confidence52
The three kernel CVEs CISA added to its exploited-bugs catalog on Friday all need local access, and the lowest-scored of them is the one STAR Labs used for privilege escalation and container escape. Red Hat has confirmed public exploit code.
Perspective Coverage
6 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence74
- Adoption68
- Hype gap−8
- Incentives38
- Confidence76
PDFik dropped --no-sandbox from its Playwright workers and kept rendering customer-submitted HTML in non-root, capability-stripped pods. Its own security auditor later wrote that the flag was mandatory.
Reality
- Evidence58
- Adoption25
- Hype gap−5
- Incentives60
- Confidence52
In an account from The New Stack, a patched runtime image still misses production a week later because every service builds its own way, and buildpacks are offered as the shared path that closes the gap.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+28
- Incentives
- Insufficient
- Confidence44
A dev.to write-up traces a build that fails only on enterprise-kernel servers to three correct components meeting badly. The seccomp profile that fixes it stays inert until the build runs on Docker's classic engine.
Reality
- Evidence50
- Adoption12
- Hype gap−15
- Incentives55
- Confidence55
A dev.to writeup takes a 15-line Flask app from 442 MB to 56.6 MB and publishes its layer sizes. The measured layers cover 74.4 MB of the cut, and the base image swap has to account for the rest.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+30
- Incentives30
- Confidence50
Cua's auth check keyed on a container variable while its bind default listened everywhere, and the pair scored 9.8. AutoAgent's blunter version had no fixed release when the records went out.
Reality
- Evidence62
- Adoption32
- Hype gap+8
- Incentives35
- Confidence55
CISA added CVE-2026-53362 to its exploited-vulnerabilities catalog on August 27. The single published account of the bug says the escape needs only unprivileged code on the node plus permission to open a UDP socket, which almost nothing is denied.
Reality
- Evidence20
- Adoption12
- Hype gap+40
- Incentives55
- Confidence30
The 39 percent comes from Wiz research with no published sample or method, and it bounds the hardened-image pitch as much as it supports it, since most critical container findings sit above the base layer.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+40
- Incentives92
- Confidence62
The container security pioneers behind a $410 million exit could not sell fewer CVEs to buyers whose budgets were already committed. The registry goes dark on October 22.
Reality
- Evidence60
- Adoption14
- Hype gap+22
- Incentives58
- Confidence55
Traefik Labs argues most CVEs in a container come from the OS packaging around the application, not the application. Its pitch is attack surface reduction rather than faster detection.
Reality
- Evidence27
- Adoption
- Insufficient
- Hype gap+38
- Incentives82
- Confidence34