logo

Public-facing Kubernetes clusters at risk of takeover thanks to Ingress-Nginx flaw

ID: 0982bfe4-740b-591c-a595-164dbc8d48dc

STIX ID: report--0982bfe4-740b-591c-a595-164dbc8d48dc

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-03-25

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Wiz disclosed critical vulnerabilities in the Ingress‑Nginx admission controller — including CVE‑2025‑1974 (CVSS 9.8) — that permit injection of malicious Nginx configuration leading to remote code execution and potential full Kubernetes cluster takeover; fixes (Ingress‑Nginx Controller 1.12.1 / 1.11.5) and mitigations (restrict admission controller network access or disable it) have been released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.