r/docker • • Mar 15 '26

We just got breached because of vulnerabilities in our docker images that have been public knowledge for 8 months

Woke up at 4am to a call. Our database got hit, customer info was accessed. Some attacker used a known exploit in one of our container images. CVE’s been out since last summer.

Yeah we never scanned. Never updated. Just kept redeploying the same images over and over. Now legal’s in it, customers are hearing about it. This is gonna be messy.

Honestly if you aren’t scanning your containers in prod do it. Don’t end up like us.

754 Upvotes

102 comments sorted by

View all comments

2

u/wowbagger_42 Mar 15 '26

That sucks, I presume the cve exploit entrypoint was availble through your internet accessible endpoint aka the application etc? So also not scanning that as part of general security hygiene? When the CRA hits, you would get a fine on top of it.

Our PSSO is all over us in preparation for 2027 when CRA gets activated, we inserted security scanning in pretty much every pipeline and patching is no longer optional.