logo

How to find Kubernetes Ingress-NGINX Controller installations on your network

ID: 68603b2f-587d-52ea-96a5-35249e3a8ba1

STIX ID: report--68603b2f-587d-52ea-96a5-35249e3a8ba1

Feed Name: runZero Blog

Threat Score
70/100

Date Published: 2026-02-03

Date Updated: 2026-04-29

Author: runZero Team

...
...

Kubernetes Security Response Committee disclosed four vulnerabilities in the Ingress‑NGINX Controller (CVE-2026-24512/24513/24514 and CVE-2026-1580) that can allow unauthenticated attackers to achieve remote code execution by exploiting input-validation and configuration-injection flaws; CVE-2026-24513 is highlighted for bypassing auth-url under certain backend header conditions. The advisory notes exploitation depends on access to the Ingress-NGINX admission controller (an optional component), clarifies that the similarly named NGINX Ingress controller is not affected, and recommends upgrading to versions 1.13.7, 1.14.3, or later while providing a runZero query to locate potentially vulnerable services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.