Enhanced Runtime Exposure Visibility for Container Images with Wiz Integrations
New article articles in ServiceNow Community
·
Sep 17, 2026
·
article
We're excited to introduce enhancements to the Wiz Container Vulnerability Response (CVR) integrations that provide richer runtime context for vulnerable container images and remove previous deployment-scale limitations.
What's New?
We've introduced two new integrations (in Sep 2026 release) that work alongside the existing Wiz Container Vulnerability Integration to create a chained workflow for discovering, mapping, and tracking vulnerable container images across your environment:
✅ Wiz Container Grouped Vulnerability Integration
Discovers active vulnerable container images and imports their unique repository-level Source IDs from Wiz. These identifiers establish a consistent image inventory that serves as the foundation for deployment tracking.
✅ Wiz Container Deployment Context Integration
Maps images to their runtime deployment locations, including clusters, namespaces, and services. It also detects new deployments and automatically creates any missing vulnerable items when deployment footprints expand.
✅ Wiz Container Vulnerability Integration (existing)
Uses the deployment context collected by the upstream integrations to create Container Vulnerable Items for all affected deployments while respecting existing granularity configurations.
These integrations are installed automatically, enabled by default, and work together to provide a more comprehensive view of container runtime exposure.
Why Was This Built?
Previously, CVIT creation for a container image was limited to deployments across 16 clusters. For customers operating large Kubernetes environments, this could result in incomplete visibility into where vulnerable images were actively running. These enhancements remove that limitation and provide a more complete view of runtime exposure, enabling security teams to better understand and prioritise risk.
What Does This Deliver?
- Unlimited Cluster Coverage - CVITs can now be created for vulnerable images deployed across any number of clusters.
- Rich Deployment Context - Security teams gain visibility into the clusters, namespaces, and services where vulnerable images are running.
- Automated Coverage Expansion - When an existing image is deployed in new locations, missing vulnerable items are automatically created.
- Accurate Tracking Without Duplication - The integrations maintain deployment relationships and update records as environments evolve without creating duplicate vulnerable items.
Improvements for Existing Customers
Customers already using container image granularity (for Namespace and Cluster fields) will automatically benefit from:
- Creation of previously missing CVITs for deployments beyond the former 16-cluster limit
- Complete deployment mappings across clusters, namespaces, and services
- Improved alignment between vulnerability findings and runtime exposure
Customers not using granularity will still gain enhanced deployment context on container discovered images, while maintaining their current vulnerable item creation behaviour.
Key Benefits
✅ Removes the previous 16-cluster limitation
✅ Expands visibility into where vulnerable images are deployed
✅ Automatically identifies and tracks newly deployed vulnerable images
✅ Improves remediation prioritisation with richer runtime context
✅ Preserves existing granularity configurations and workflows
✅ Eliminates visibility gaps in large-scale Kubernetes environments
The enhanced runtime exposure capability is available to all customers entitled to Container Vulnerability Response. The integrations are installed automatically and enabled by default, allowing you to immediately benefit from more complete deployment visibility and vulnerability tracking.
ContainerSecurity #Wiz #ContainerVulnerabilityResponse #Kubernetes #CloudSecurity #RuntimeExposure #SecurityOperations
https://www.servicenow.com/community/secops-articles/enhanced-runtime-exposure-visibility-for-container-images-with/ta-p/3599152