String of defects in popular Kubernetes component puts 40% of cloud environments at risk
ID: 27dad5a2-fe9c-5a2a-a855-ce30e6deb99e
STIX ID: report--27dad5a2-fe9c-5a2a-a855-ce30e6deb99e
Feed Name: CyberScoop
Security researchers disclosed five vulnerabilities in the widely used Ingress Nginx Controller for Kubernetes — including a critical unauthenticated RCE (CVE-2025-1974, CVSS 9.8) — that can be chained with configuration-injection flaws to allow cluster takeover and access to secrets. Patches have been released, but scans found thousands of potentially exposed controllers and public proof-of-concept exploits have appeared, creating a high risk for unpatched, publicly accessible clusters.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
