Cloud Risks

AnalyticsYesterday, 13:29
Wiz analysts prepared a report on the risks facing cloud technologies in 2026. The researchers identify two trends shaping the modern threat landscape: an expanding attack surface and less time available for response.
Key figures and facts:
AI is already becoming an integral part of cloud infrastructure and development: 81% of cloud environments use managed AI services, 90% use self-hosted AI solutions, and 80% of organizations use MCP servers. The same percentage of organizations use AI extensions for IDEs. At the same time, 71% use at least one AI coding assistant. Meanwhile, AI adoption expands the attack surface by introducing new trust relationships that can propagate across cloud environments.
Cloud environments generate large volumes of security events, but contextual analysis can significantly narrow down which ones require a prioritized response. After accounting for factors such as internet exposure, access to sensitive data, privilege-escalation opportunities, and related attack paths, the number of prioritized findings fell by 53–67%, depending on the category.
Among identified high- and critical-severity issues, 33% involved information disclosure, 23% involved secrets and credentials, and 22% involved unauthorized access. Together, these categories account for 78%, while remote code execution accounts for only 10%. At the same time, analysis of real-world cloud incidents shows that vulnerability exploitation remains the primary method of initial access, accounting for 40% of cases. Exposed secrets account for another 21%, and misconfigurations for 19%.
In cloud environments, the consequences of a compromise are largely determined by the relationships between access, privileges, and trusted connections: 30% of observed environments had at least one externally exposed high-impact machine, while in 19% of environments, externally accessible software was connected to IAM entities with access to sensitive internal resources.
Cloud environments use thousands of different applications and dependencies, yet exploitable vulnerabilities are concentrated in a relatively small number of technologies: 35% of identified high- and critical-severity vulnerabilities with public exploits were found in the three most prevalent vendors in the sample, while 81% of all exploitable vulnerabilities were concentrated in just 52% of the software products analyzed.
The study shows that cloud risks are becoming increasingly interconnected. AI expands the attack surface, while a significant portion of real-world risk lies not in traditional RCE vulnerabilities but in access, secrets, and misconfigurations. Therefore, prioritizing remediation based solely on individual metrics such as CVSS is no longer sufficient—it is important to consider external exposure, opportunities for lateral movement, and the potential impact of a compromise.
The attached report also includes a 13-level contextual risk prioritization matrix that helps structure these factors and determine which threats should be addressed first.
Vendors
Wiz