View and remediate vulnerabilities for running containers
In brief
The article was revised for clearer wording, updated metadata, simplified prerequisite instructions, and refreshed links and step descriptions. The documented component combinations and recommendation workflow were clarified.
What Defender admins need to know
Administrators can use the updated instructions to review and remediate Kubernetes container vulnerabilities; no configuration change is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
View and remediate vulnerabilities for running containers
Defender for Cloud helps you identifyfind and prioritizefix vulnerabilities in images currently used bythat your Kubernetes workloads running on Kubernetes clusters.use.
To generatecreate these findings, Defender for Cloud first builds an inventorya list of your Kubernetes workloads by usingworkloads. It uses supported discovery and protection components, and correlatescomponents to do this. Then it matches that inventory withlist against known vulnerability data for the images used by those workloads.workloads run.
Vulnerability findingsFindings for running containers are shownappear as security recommendations in Defender for Cloud.recommendations. The following steps in this article use the Flat list recommendations view, which shows recommendationsresults at the affected-resource level. Learn more about reviewing recommendations by title or by resource.
Prerequisites
Before you begin, make sure thatenable Defender for Containers or Defender CSPM is enabled on your subscription withsubscription. Turn on one of the followingthese component combinations toggled on:sets:
- Registry access and either Kubernetes API access or Defender sensor
to map registry-. This option links scanned registry images to running workloads. - Agentless scanning for machines and either Kubernetes API access or Defender sensor. This option checks for
registry-agnosticruntimevulnerability assessment.vulnerabilities without a registry.
View vulnerabilities for running containers
Select a recommendation.
Review the
recommendationdetails, includingtheriskinformation, remediation guidance,info, fix steps, andrecommendationmetadata.Select the Associated CVEs tab to
reviewsee the CVEsassociated with the recommendation.for that item.Select a CVE to view
details such asits severity, affected components, and fixversion information.version.
Related content
To find all containers
affected bywith aspecificgiven vulnerability, see Group recommendations by title.To
remediatefix vulnerabilities, see Remediate recommendations.
\ No newline at end of file
View and fix vulnerabilities for registry images \ No newline at end of file
\ No newline at end of file
@@ -2,29 +2,29 @@ title: View and remediate vulnerabilities for running containers description: Learn how to view and remediate vulnerability findings for running containers in Microsoft Defender for Cloud. ms.service: defender-for-cloud-ms.custom: build-2023, sfi-image-nochange+ms.custom: build-2023, sfi-image-nochange, msecd-doc-authoring-1013 ms.topic: how-to-ms.date: 06/14/2026+ms.date: 07/03/2026 #customer intent: As a security administrator, I want to review vulnerability findings for images used by running containers so I can prioritize and remediate issues that affect active Kubernetes workloads. ai-usage: ai-assisted --- # View and remediate vulnerabilities for running containers -Defender for Cloud helps you identify and prioritize vulnerabilities in images currently used by workloads running on Kubernetes clusters.+Defender for Cloud helps you find and fix vulnerabilities in images that your Kubernetes workloads use. -To generate these findings, Defender for Cloud builds an inventory of your Kubernetes workloads by using supported discovery and protection components, and correlates that inventory with vulnerability data for the images used by those workloads.+To create these findings, Defender for Cloud first builds a list of your Kubernetes workloads. It uses supported discovery and protection components to do this. Then it matches that list against known vulnerability data for the images those workloads run. -Vulnerability findings for running containers are shown as security recommendations in Defender for Cloud. The steps in this article use the **Flat list** recommendations view, which shows recommendations at the affected-resource level. Learn more about [reviewing recommendations by title or by resource](review-security-recommendations.md#recommendation-title-view).+Findings for running containers appear as security recommendations. The following steps use the **Flat list** view, which shows results at the resource level. Learn more about [reviewing recommendations by title or by resource](review-security-recommendations.md#recommendation-title-view). > [!NOTE]-> During the transition from grouped to individual recommendations, you might see both recommendation formats in the portal. Learn more about [transitioning from grouped to individual recommendations](transition-grouped-individual-recommendations.md).+> You might see both grouped and individual recommendation formats in the portal during this transition. Learn more about [transitioning from grouped to individual recommendations](transition-grouped-individual-recommendations.md). ## Prerequisites -Before you begin, make sure that [Defender for Containers](defender-for-containers-enable-plan.md) or [Defender CSPM](tutorial-enable-cspm-plan.md) is enabled on your subscription with one of the following component combinations toggled on:+Before you begin, enable [Defender for Containers](defender-for-containers-enable-plan.md) or [Defender CSPM](tutorial-enable-cspm-plan.md) on your subscription. Turn on one of these component sets: -- **Registry access** and either **Kubernetes API access** or **Defender sensor** to map registry-scanned images to running workloads.-- **Agentless scanning for machines** and either **Kubernetes API access** or **Defender sensor** for registry-agnostic runtime vulnerability assessment.+- **Registry access** and either **Kubernetes API access** or **Defender sensor**. This option links scanned registry images to running workloads.+- **Agentless scanning for machines** and either **Kubernetes API access** or **Defender sensor**. This option checks for runtime vulnerabilities without a registry. ## View vulnerabilities for running containers @@ -50,18 +50,18 @@ To view vulnerabilities for a running container: 1. Select a recommendation. -1. Review the recommendation details, including the risk information, remediation guidance, and recommendation metadata.+1. Review the details, including risk info, fix steps, and metadata. -1. Select the **Associated CVEs** tab to review the CVEs associated with the recommendation.+1. Select the **Associated CVEs** tab to see the CVEs for that item. -1. Select a CVE to view details such as severity, affected components, and fix version information.+1. Select a CVE to view its severity, affected components, and fix version. ## Related content -- To find all containers affected by a specific vulnerability, see [Group recommendations by title](review-security-recommendations.md#resource-views).+- To find all containers with a given vulnerability, see [Group recommendations by title](review-security-recommendations.md#resource-views). -- To remediate vulnerabilities, see [Remediate recommendations](implement-security-recommendations.md).+- To fix vulnerabilities, see [Remediate recommendations](implement-security-recommendations.md). -- [Build Cloud Security Explorer queries for container vulnerabilities](cloud-security-explorer-container-vulnerabilities.md)+- [Query container vulnerabilities in Cloud Security Explorer](cloud-security-explorer-container-vulnerabilities.md) -- [View and remediate vulnerabilities for registry images](view-and-remediate-vulnerability-registry-images.md)\ No newline at end of file+- [View and fix vulnerabilities for registry images](view-and-remediate-vulnerability-registry-images.md)\ No newline at end of file 