Port Scans Reveal Over 1.4M Docker Hosts Exposed, Far Eclipsing Fingerprint Counts
A ZoomEye internet scan conducted on September 26, 2026 found stark discrepancies depending on how Docker exposure was queried: a port-based search for port 2375 returned over 1.4 million results, while an application fingerprint query for Docker returned just 13,193. Port 2376, used for encrypted Docker daemon connections, yielded an even larger count of 1.75 million hosts. The gap exists because a Docker daemon listening on a TCP port has no requirement to identify itself in a way fingerprint matchers recognise. Security researchers warn that the Docker daemon does not authenticate clients at the API level, meaning any reachable client can issue commands equivalent to local administrator access, including mounting host directories. Experts recommend running both port-based and fingerprint-based queries in parallel to accurately size exposure, rather than relying on either method alone.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in