Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication

Five significant security flaws in the Ingress NGINX Controller for Kubernetes have been revealed. These flaws might lead to unauthenticated remote code execution, immediately endangering over 6,500 clusters by exposing the component to the public internet.

Assigned a CVSS score of 9.8, the vulnerabilities (CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, and CVE-2025-1974) have been jointly dubbed IngressNightmare by cloud security company Wiz. Notably, NGINX Ingress Controller, another ingress controller solution for NGINX and NGINX Plus, is unaffected by the flaws.

When these flaws are exploited, attackers get illegal access to all secrets kept in all namespaces within the Kubernetes cluster, potentially leading to cluster takeover read more about Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *