
If you're running critical or multi-tenant workloads on containers, you're playing with fire. The CVE record keeps proving it: - CVE-2024-21626 — Leaky Vessels: runc container escape, host filesystem access - CVE-2025-23266 — NVIDIAScape: CVSS 9.0, triggered by a 3-line Dockerfile - CVE-2025-52881 — runc procfs write-redirect: full breakout, actively exploited in the wild by mid-2026 - CVE-2025-38617 — Linux kernel packet-socket: full container escape via user namespaces This is not a 2024 phenomenon that someone will eventually fix. The November-2025 runc trio (CVE-2025-31133 / -52565 / -52881) moved from disclosure to confirmed in-the-wild exploitation, affecting Docker, containerd and every major managed Kubernetes service. Escapes never stopped — 2024-2025 brought a fresh surge, and by 2026 the worst of them are being exploited for real. Containers don't contain. ⚠️ 📄 Full blog post: https://unikraft.com/blog/the-mighty-microvm
Post summary
The post lists several container escape CVEs and asserts that they are actively exploited in the wild, highlighting ongoing risks for containerized workloads.




