logo

Critical Unauthenticated Remote Code Execution Vulnerabilities inIngress NGINX

ID: 6f8f821f-e7af-5370-a02d-2c6936f99a5c

STIX ID: report--6f8f821f-e7af-5370-a02d-2c6936f99a5c

Feed Name: Kudelski Security

Threat Score
85/100

Date Published: 2025-03-25

Date Updated: 2026-07-24

...
...

Wiz Research disclosed multiple critical unauthenticated RCE vulnerabilities in the Ingress NGINX Controller ("IngressNightmare") that permit arbitrary command execution via unsanitized ingress annotations and the admission controller, potentially exposing cluster-wide secrets and enabling full Kubernetes cluster compromise; immediate mitigation recommended includes upgrading affected controllers (prior to 1.12.1 and 1.11.5), restricting admission webhook access, and increased monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.