Critical 'IngressNightmare' Vulns Imperil Kubernetes Environments
ID: 357d004e-92cd-5e70-bad8-92f8204e88f7
STIX ID: report--357d004e-92cd-5e70-bad8-92f8204e88f7
Feed Name: Dark Reading
Kubernetes Ingress NGINX Controller has four critical vulnerabilities (notably CVE-2025-1974) that allow unauthenticated attackers to inject NGINX configuration and, when chained, achieve remote code execution and full cluster takeover; the flaws affect an estimated 6,500 Internet-facing clusters (~41%) and carry a CVSS up to 9.8 — administrators are urged to upgrade to fixed versions (1.12.1, 1.11.5, v1.10.7), restrict admission controller network access, or disable it until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
