Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Docker, Inc

Docker, Inc Vendor Cyber Rating & Cyber Score

docker.com

At Docker, we simplify the lives of developers who are making world-changing apps. Docker helps developers bring their ideas to reality by conquering the complexity of app development. We simplify and accelerate workflows with an integrated development pipeline and application components. Actively used by millions of developers around the world, Docker Desktop and Docker Hub provide unmatched simplicity, agility and choice.


Docker, Inc A.I CyberSecurity Scoring

Docker, Inc
Company Information
Website:http://www.docker.com
Employees number:949
Number of followers:759,100
NAICS:5112
Industry Type:Software Development
Homepage:docker.com
Docker, Inc Risk Score (AI oriented)
Between 700 and 749
logo
Docker, IncSoftware Development
Updated:
23/04/2026
738/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Docker, Inc Global Score (TPRM)
xxxx
logo
Docker, IncSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Docker, Inc
Docker, IncModerate
Current Score
738Ba (MODERATE)
01000
5 incidents
-8.25 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
741Before Incident
MAY 2026
739Before Incident
APRIL 2026
757Before Incident
Cyber Attack
22 Apr 2026Docker, Inc
Checkmarx, Docker and GitHub: New Checkmarx supply-chain breach affects KICS analysis tool

Malicious Hackers Compromise Checkmarx KICS Tool to Steal Developer Secrets

738After Incident
CRITICAL-19
CHEDOCGIT1776961598
Malicious Hackers Compromise Checkmarx KICS Tool to Steal Developer Secrets Hackers infiltrated the Checkmarx KICS (Keeping Infrastructure as Code Secure) tool, a popular open-source scanner for identifying vulnerabilities in code, dependencies, and configurations. The attack targeted Docker images, VS Code extensions, and Open VSX extensions, deploying malware designed to harvest sensitive data from developer environments. Security firm Socket uncovered the breach after Docker flagged malicious images in the official checkmarx/kics Docker Hub repository. The compromise extended to VS Code and Open VSX extensions, which secretly downloaded a hidden "MCP addon" from a hardcoded GitHub URL. This addon executed a multi-stage malware (mcpAddon.js) that stole credentials, including: - GitHub tokens - Cloud credentials (AWS, Azure, Google Cloud) - npm tokens - SSH keys - Claude configs - Environment variables The stolen data was encrypted and exfiltrated to audit.checkmarx[.]cx, a domain mimicking legitimate Checkmarx infrastructure. Attackers also automatically created public GitHub repositories for data exfiltration. The malicious Docker images were available for 83 minutes on April 22, 2026 (14:17:59–15:41:31 UTC) before being restored to legitimate versions. The fake v2.1.21 tag was removed entirely. While the TeamPCP hacking group, linked to previous supply-chain attacks (Trivy, LiteLLM), claimed responsibility, researchers found only pattern-based correlations and could not confirm attribution. Checkmarx confirmed the incident in a security bulletin, stating that all malicious artifacts were removed, exposed credentials were revoked, and an investigation with external experts is ongoing. The company advised users to block access to suspicious IPs (91.195.240.123, 94.154.172.43), revert to pinned SHAs, and rotate compromised secrets. Safe versions of affected tools include: - DockerHub KICS v2.1.20 - Checkmarx ast-github-action v2.3.36 - Checkmarx VS Code extensions v2.64.0 - Checkmarx Developer Assist extension v1.18.0
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Data Theft, Credential Harvesting
IMPACT
Data Compromised: Credentials (GitHub tokens, cloud credentials, npm tokens, SSH keys, Claude configs, environment variables)Docker imagesVS Code extensionsOpen VSX extensionsOperational Impact: Potential unauthorized access to developer environments and cloud resourcesBrand Reputation Impact: Moderate to High (supply chain compromise of a security tool)Identity Theft Risk: High (exposure of PII and credentials)
DATA BREACH
CredentialsEnvironment VariablesConfiguration FilesSensitivity Of Data: High (GitHub tokens, cloud credentials, SSH keys, PII)
MARCH 2026
757Before Incident
FEBRUARY 2026
761Before Incident
Vulnerability
10 Feb 2026Docker, Inc
Docker and Darktrace: Threat Actors Exploiting React2Shell Vulnerability Using AI-Generated Malware

AI-Generated Malware Exploits 'React2Shell' in Low-Skill Cyberattack Campaign

756After Incident
LOW-5
DARDOC1770731539
AI-Generated Malware Exploits "React2Shell" in Low-Skill Cyberattack Campaign Darktrace’s CloudyPots honeypot network recently uncovered an active malware campaign leveraging AI-generated tools to exploit the React2Shell vulnerability, marking a concerning evolution in cybercrime tactics. The attack, detected in a misconfigured Docker environment, demonstrates how large language models (LLMs) are lowering the barrier for threat actors to deploy sophisticated exploits with minimal technical expertise. The intrusion began when attackers targeted an exposed Docker daemon a common cloud misconfiguration via its API. The threat actor deployed a container named "python-metrics-collector" to blend in with legitimate services, then installed tools like curl, wget, and python3 to fetch payloads. The attack unfolded in two stages: 1. Dependency Retrieval: A Pastebin URL delivered a list of required Python packages. 2. Payload Execution: A Python script, hosted on a GitHub Gist under the banned user "hackedyoulol", was executed after redirecting from smplu[.]link. Analysis revealed the script was likely AI-generated, featuring verbose comments and an "educational" disclaimer a tactic to bypass LLM safety filters. Tools like GPTZero confirmed 76% of the code was machine-written, with a clean, structured design that exploited React2Shell by forcing exceptions to expose command output. Despite its advanced delivery, the campaign’s goal was simple: cryptocurrency mining. The script deployed XMRig (v6.21.0) to mine Monero (XMR) via the supportxmr pool. While the financial gain was minimal 0.015 XMR (~£5) from 91 infected hosts the operational impact was significant: a low-skilled attacker compromised nearly 100 systems using AI-generated tools. Unlike typical Docker threats, the malware lacked self-propagation capabilities, relying instead on a centralized "spreader server" linked to a residential IP (49[.]36.33.11) in India. This suggests manual or scripted management of the campaign. The incident underscores a critical shift in cyber threats, where AI-driven "vibecoding" enables rapid, custom malware development. For defenders, this highlights the need for behavioral detection and proactive patching, as static signatures may struggle against the endless variations LLMs can produce. Indicators of Compromise (IoCs): - Spreader IP: 49[.]36.33.11 - Malware host: smplu[.]link - Hashes: - 594ba70692730a7086ca0ce21ef37ebfc0fd1b0920e72ae23eff00935c48f15b - d57dda6d9f9ab459ef5cc5105551f5c2061979f082e0c662f68e8c4c343d667d
INCIDENT DETAILS -
TYPE
Malware Campaign
MOTIVATION
Financial gain (cryptocurrency mining)
IMPACT
Financial Loss: 0.015 XMR (~£5)Systems Affected: 91 infected hostsOperational Impact: Significant (compromised systems used for mining)
FEBRUARY 2026
765Before Incident
Vulnerability
04 Feb 2026Docker, Inc
Docker: The DockerDash Vulnerability: Understanding Its Impact on Docker Desktop and CLI

DockerDash: Docker Desktop and CLI Vulnerability Exposes Systems to Arbitrary Code Execution and Data Theft

760After Incident
CRITICAL-5
DOC1770222802
Docker Desktop and CLI Vulnerability Exposes Systems to Arbitrary Code Execution and Data Theft A critical security flaw, dubbed DockerDash, was discovered in Docker Desktop and the Docker Command-Line Interface (CLI), specifically within the Ask Gordon AI assistant integrated into these tools. Identified by cybersecurity firm Noma Labs, the vulnerability posed severe risks, including arbitrary code execution and unauthorized access to sensitive data, before being patched. ### Scope and Impact of the Vulnerability Docker is widely used across industries for containerized application deployment, making this flaw particularly concerning. The DockerDash vulnerability allowed attackers to: - Execute arbitrary code within applications running on Docker Desktop or CLI, enabling malicious scripts or unauthorized activities. - Move laterally within networked environments, expanding the potential attack surface. - Exfiltrate sensitive data, including confidential business information, user credentials, and intercepted data traffic processed by Ask Gordon. ### Discovery and Response Noma Labs uncovered the flaw and alerted Docker, which swiftly deployed a patch to mitigate the risk. The security firm praised Docker’s rapid response, highlighting the importance of proactive vulnerability management in developer tools. ### Broader Security Implications The incident underscores the need for continuous monitoring and timely updates in software dependencies, particularly in widely adopted platforms like Docker. As reliance on containerization grows, vulnerabilities like DockerDash serve as a reminder of the evolving threats in cloud and application security.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Confidential business information, user credentials, intercepted data trafficSystems Affected: Docker Desktop, Docker CLIOperational Impact: Arbitrary code execution, lateral movement within networked environments
DATA BREACH
Confidential business informationUser credentialsIntercepted data trafficSensitivity Of Data: HighData Exfiltration: Yes
JANUARY 2026
769Before Incident
Vulnerability
01 Jan 2026Docker, Inc
Docker: Docker Authorization Bypass Flaw Exposed Hosts to Potential Attackers

Docker Engine Vulnerability (CVE-2026-34040) Exposes Hosts to Authorization Bypass Risks

765After Incident
CRITICAL-4
DOC1775644091
Docker Engine Vulnerability (CVE-2026-34040) Exposes Hosts to Authorization Bypass Risks A high-severity security flaw in Docker Engine, tracked as CVE-2026-34040, has been identified, enabling attackers to bypass authorization plugins (AuthZ) by manipulating API request bodies. The vulnerability carries a "High" severity rating, though its exploitation likelihood remains low. The issue stems from how the Docker daemon processes oversized request bodies. Attackers with low-level access can craft malicious API requests, prompting the daemon to strip the request body before forwarding it to the AuthZ plugin. Without the necessary data, the plugin may approve actions it would typically block, effectively allowing unauthorized commands to execute. This flaw is a regression of a previous Docker authorization vulnerability (CVE-2024-41110) and affects environments relying on AuthZ plugins for access control. Systems not using these plugins are unaffected. The vulnerability impacts all Docker Engine versions prior to 29.3.1 and could be exploited via a compromised container or low-privilege account to escalate privileges, modify host configurations, or access sensitive data. Docker has released version 29.3.1 to patch the issue. For organizations unable to upgrade immediately, workarounds include discontinuing AuthZ plugins that depend on request body inspection or restricting Docker API access to trusted users under the principle of least privilege. The flaw was responsibly disclosed by security researchers, with remediation led by the Docker development community.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Sensitive data access possibleSystems Affected: Docker Engine versions prior to 29.3.1Operational Impact: Unauthorized command execution, privilege escalation, host configuration modification
DATA BREACH
Sensitivity Of Data: Sensitive data
DECEMBER 2025
769Before Incident
NOVEMBER 2025
769Before Incident
OCTOBER 2025
769Before Incident
SEPTEMBER 2025
769Before Incident
AUGUST 2025
769Before Incident
JULY 2025
769Before Incident
JUNE 2025
770Before Incident
Vulnerability
16 Jun 2025Docker, Inc
Docker

Critical Path Traversal and DLL Hijacking Vulnerabilities in Docker Compose and Docker Desktop

768After Incident
CRITICAL-2
DOC2992329103025
Docker was affected by CVE-2025-62725, a critical path traversal vulnerability in Docker Compose (fixed in v2.40.2) that allowed attackers to escape the tool’s cache directory and write arbitrary files on the host system by exploiting malicious OCI-based Compose artifacts. The flaw stemmed from improper handling of layer annotations, enabling attackers to traverse outside the intended directory and overwrite files where the Compose process had write permissions. This posed a severe risk to workflows relying on Compose—including CI/CD pipelines, cloud workspaces, and enterprise build systems—potentially leading to unauthorized code execution, system compromise, or supply-chain attacks if exploited. Separately, Docker also patched EUVD-2025-36191, a DLL hijacking vulnerability in its Windows Installer (Desktop Installer.exe), which allowed attackers to escalate privileges by planting malicious DLLs in the user’s Downloads folder. Both flaws underscored the risks of unvalidated input handling and insecure default configurations, reinforcing the need for strict path sanitization and timely updates. While no active exploits were reported, the vulnerabilities exposed millions of Docker users to potential system takeover, data manipulation, or lateral movement within networks if left unpatched.
INCIDENT DETAILS -
TYPE
VulnerabilityPath TraversalDLL Hijacking
IMPACT
Docker Compose (OCI artifact processing)Docker Desktop (Windows Installer)Operational Impact: Potential arbitrary file writes on host systems (Compose) or privilege escalation via DLL hijacking (Desktop).Brand Reputation Impact: Moderate (repeated high-severity vulnerabilities in Docker products may erode trust).

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Docker, Inc ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Docker, Inc's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Docker, Inc's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Docker, Inc ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Docker, Inc's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?