Home Cyber Security

Wiz research finds cloud risk concentrated in access, credentials and small pool of technologies

Cloud security teams may be able to significantly reduce their remediation workloads by concentrating on a relatively small proportion of technologies and attack paths, rather than attempting to treat every high-severity alert equally, according to research from Wiz.

The company’s State of Cloud Risk 2026 report found that exploitable risk across enterprise cloud environments is far more concentrated than raw security alert volumes suggest.

Wiz Research found 81 per cent of observed exploitable vulnerabilities were concentrated within 52 per cent of analysed software products, while the three most represented vendors accounted for approximately 35 per cent of observed high and critical cloud vulnerabilities with publicly available exploits.

The findings come as security teams face growing numbers of alerts alongside rapidly shrinking windows between vulnerability disclosure and exploitation.

Wiz said the combination means organisations can no longer rely simply on patching vulnerabilities according to their severity rating.

Its analysis found contextual information dramatically reduced the number of cloud security findings requiring urgent action.

When factors such as internet exposure, sensitive data access, privilege escalation opportunities and attack paths were taken into account, high-priority weak credential findings fell by 67 per cent.

Secrets exposure findings declined by 60 per cent, unauthorised access by 58 per cent and high or critical RCE exposure findings by 53 per cent.

According to Wiz, the results demonstrate that many high-severity security findings lack the surrounding conditions required to give attackers a meaningful opportunity.

Instead, exploitable risk was heavily concentrated around access.

Information disclosure accounted for 33 per cent of observed high and critical exploitable issues, credentials and secrets for 23 per cent and unauthorised access for 22 per cent.

Together, those categories represented approximately 78 per cent of observed exploitable risk. RCE vulnerabilities accounted for less than 10 per cent.

The figures are significant because software vulnerability patching has traditionally consumed a large share of security teams’ remediation resources.

Wiz said vulnerability exploitation nevertheless remains a major initial access vector. Data from its 2026 Cloud Threats Retrospective found it accounted for 40 per cent of documented cloud intrusions between February and December 2025.

However, exposed secrets accounted for 21 per cent and misconfigurations 19 per cent, together matching vulnerabilities’ 40 per cent share.

The report argues the eventual impact of a cloud intrusion is also increasingly determined by privilege and reachability rather than the initial point of entry.

Thirty per cent of observed cloud environments contained at least one externally exposed high-impact machine, while 19 per cent contained exposed software connected directly to IAM identities with access to sensitive internal assets.

Wiz said trusted relationships between systems can enable attackers to expand an initial compromise through privileged identities, sensitive data access, cloud control planes, service accounts and automated workflows.

The report points to the Shai-Hulud and S1ngularity campaigns as examples where trusted relationships, identity abuse and cloud permissions affected the potential blast radius of an attack.

Wiz is recommending security teams prioritise combinations of exposure, privilege and downstream impact rather than addressing isolated findings purely according to CVSS scores.

It has outlined a 13-tier contextual risk prioritisation model, with the highest priority given to findings where initial access vulnerabilities, internet exposure, likely exploitability and business impact intersect.

The company said the approach is intended to help defenders concentrate engineering resources on the smaller number of issues capable of producing meaningful compromise.

As AI adoption adds further services, identities and integrations to cloud environments, Wiz argues contextual prioritisation will become increasingly important to prevent security teams being overwhelmed by alert volume.