logo

String of defects in popular Kubernetes component puts 40% of cloud environments at risk

ID: 27dad5a2-fe9c-5a2a-a855-ce30e6deb99e

STIX ID: report--27dad5a2-fe9c-5a2a-a855-ce30e6deb99e

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2025-03-26

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Security researchers disclosed five vulnerabilities in the widely used Ingress Nginx Controller for Kubernetes — including a critical unauthenticated RCE (CVE-2025-1974, CVSS 9.8) — that can be chained with configuration-injection flaws to allow cluster takeover and access to secrets. Patches have been released, but scans found thousands of potentially exposed controllers and public proof-of-concept exploits have appeared, creating a high risk for unpatched, publicly accessible clusters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.