Azure running container images should have vulnerabilities resolved

HIGH

Ensures container images running in Azure are scanned and have known vulnerabilities resolved.

What does this mean?

This recommendation ensures that container images actively running in Azure environments are free from known vulnerabilities. Images should be regularly scanned and updated to address newly discovered CVEs.

Benefits of implementation

  • Provides continuous vulnerability assessment of running workloads
  • Reduces the window of exposure to known CVEs
  • Required by Defender for Cloud container security

Drawbacks and considerations

  • Continuous scanning generates ongoing operational overhead
  • False positives may require investigation
  • Remediation may lag behind new vulnerability disclosures

Implementation

Implementation guidance coming soon.

Related recommendations will be linked here.

Frameworks

Details
Risk Level
HIGH
Category
Container Security
Azure Resource

Frameworks
2 frameworks
Last updated
2026-02-12