← All Posts
DevOps6 min read

Kubernetes Container Management in 2026: What SMBs Need to Know

Afocal Solutions·

Forty-six percent of organizations have lost revenue or customers due to a Kubernetes security incident. That's not a hypothetical risk—it's the current reality facing every company running containers in production. And if you're an SMB thinking container orchestration is someone else's problem, the August release of Kubernetes v1.37 and a 282% spike in Kubernetes-targeted attacks should change your calculus.

Why Kubernetes Security Incidents Are Spiking for Small and Mid-Sized Businesses

The number of Kubernetes-based attack attempts has increased by 282 percent in just one year, according to Palo Alto Networks' Unit 42. The IT sector is by far the hardest hit, with 78 percent of all malicious activity targeting this sector.

What's driving this? Attackers are increasingly targeting the identities running within Kubernetes clusters—specifically service account tokens. These tokens grant pods access to the Kubernetes API. Anyone who obtains such a token may have direct access to the entire cluster infrastructure.

In 22 percent of cloud environments in 2025, suspicious activity indicative of token theft was detected. Unit 42 observed a breach of a crypto exchange in mid-2025 linked to Slow Pisces (also known as Lazarus), a North Korean state-sponsored group with financial motives.

SMBs often assume they're too small to target. The data says otherwise. Attackers scan for misconfigured clusters regardless of company size, and smaller organizations typically have fewer security controls in place.

Kubernetes Adoption Has Crossed the Enterprise Threshold

According to the CNCF's Annual Cloud Native Survey released in January 2026, 82% of container users now run Kubernetes in production. Additionally, 94% are either running, piloting, or evaluating it.

98% of surveyed organizations reported adopting cloud native techniques in some form, and 77% of Fortune 100 companies now run Kubernetes in production.

But here's the problem for SMBs: 91% of all Kubernetes users come from organizations with more than 1,000 employees. Smaller companies with under 1,000 employees account for just 9% of adoption, often limited by resource constraints and simpler infrastructure needs.

79% of Kubernetes users run managed services like Amazon EKS, Google GKE, or Azure AKS rather than self-managed clusters. This is the path most SMBs should take—the operational burden of running your own control plane rarely makes sense below a certain scale.

Critical Kubernetes Vulnerabilities You Must Patch Now

To prioritize the safety and security of the ecosystem, Kubernetes SIG Network and the Security Response Committee retired Ingress NGINX on March 24, 2026. Since that date, there have been no further releases, no bugfixes, and no updates to resolve any security vulnerabilities discovered.

If you're still running Ingress NGINX, you're operating on deprecated, unsupported infrastructure. Migration to Gateway API or alternative ingress controllers is no longer optional.

The Kubernetes Security Response Committee alerted users to four issues affecting the Ingress controller. Acting as an Nginx-based gatekeeper, Ingress-Nginx manages external access to services within the cluster using advanced routing rules.

Most of the reported issues, including CVE-2026-24512 and CVE-2026-24514, affect how the controller parses and applies user-supplied ingress configuration or HTTP request data. CVE-2026-24513 had the most pressing security rating with a "high" ranking of CVSS 8.8.

A vulnerability also exists in the NodeRestriction admission controller that allows a compromised node to create mirror pods accessing unauthorized dynamic resources, potentially leading to privilege escalation. A separate security issue was discovered where malicious or compromised pods could bypass network restrictions enforced by network policies during namespace deletion.

Container Vulnerability Management for Regulated Industries

87% of container images contain high or critical security vulnerabilities. For SMBs in HIPAA-regulated healthcare or pursuing CMMC certification, this isn't just a technical problem—it's a compliance risk.

Organizations that operate under HIPAA, PCI-DSS, or similar regulations need to demonstrate that data is safeguarded through the use of short-lived containers. By adopting container vulnerability management process steps—like scanning, patch logs, and documented fix intervals—businesses show compliance with mandated security. Lack of proper checks on containers may lead to audit failure and potentially hefty fines.

The practical implementation: integrate image scanning into your CI/CD pipeline, establish baseline policies for what gets deployed, and create an auditable trail of remediation activities. Tools like Trivy (despite the recent supply chain compromise that affected it) or Snyk can automate most of this if configured properly.

What Kubernetes v1.37 Means for Your Operations

Kubernetes v1.37.0 was released on August 26, 2026, with an end-of-life date of October 28, 2027. The release graduated the SELinuxMount feature gate to GA. The feature is enabled by default in v1.37, which may break existing workloads in clusters with SELinux enabled.

The three most operationally significant developments from recent releases: In-Place Pod Resizing reaching GA (eliminates restart-on-resize), Sidecar Containers reaching GA (proper lifecycle management for init containers), and Dynamic Resource Allocation advancing to beta with structured parameters.

In-Place Pod Resizing is the change most SMBs will feel immediately. Previously, changing CPU or memory requests/limits required killing and restarting pods. Now you can adjust resources on running workloads—critical for applications where restarts cause customer-facing disruption.

For teams running AI/ML workloads: Kubernetes is becoming the de facto orchestration layer and platform for AI as more organizations run inference workloads on clusters across clouds and on-prem. The findings illustrate how Kubernetes has become the common denominator for cloud native scale, stability, and innovation, especially as organizations bring AI workloads into production environments.

Building a Container Strategy That Doesn't Burn Out Your Team

The reality for most SMBs: the real question isn't whether they should use Kubernetes but how to run it safely, efficiently, and at scale without burning out in-house teams.

Start with managed Kubernetes. EKS, GKE, and AKS handle control plane operations, freeing your team to focus on workload security and application delivery. Layer in GitOps practices—58% of self-identified "cloud native innovators" now use GitOps extensively for production deployment.

For security, implement these baseline controls:

  • Enable Pod Security Standards (restricted mode for production namespaces)
  • Use network policies with deny-all defaults
  • Rotate service account tokens and never mount them when unnecessary
  • Run continuous image scanning in your pipeline, blocking deployments that fail policy

Key Takeaways

  • Patch Ingress NGINX or migrate immediately: It's been deprecated since March 2026 and receives no security updates
  • Assume you're a target: 282% increase in Kubernetes attacks means automated scans will find your misconfigurations
  • Choose managed Kubernetes: 79% of users do, and the operational savings outweigh the slight cost premium for SMBs
  • Integrate security into CI/CD: With 87% of container images containing critical vulnerabilities, shift-left scanning is non-negotiable

Container orchestration has moved from "innovative" to "expected." The question is whether you're running it securely enough to avoid becoming part of next year's breach statistics. If your team is stretched thin managing Kubernetes alongside everything else, Afocal's Managed DevOps services can close the gap—handling the infrastructure complexity so you can focus on shipping product.

Want to learn more about how Afocal can help your business?

Book a Free Audit

Your next breach is preventable.

Let's talk about your security posture. No commitment, just a conversation with a practitioner.