As cited
Copy frozen at (site build).
vulnerabilities
IngressNightmare: CVE-2025-1974 - 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX
A critical remote code execution vulnerability (CVE-2025-1974) with a 9.8 CVSS score exists in Ingress NGINX, affecting over 40% of cloud environments and potentially enabling complete cluster takeover. The vulnerability is unauthenticated, allowing attackers to execute code without credentials. Patch deployment is required to remediate the exposure.
Why it matters: Organizations running Ingress NGINX controllers are at immediate risk of total cluster compromise; this requires urgent patching and assessment of current deployments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
IngressNightmare: CVE-2025-1974 - 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX
A critical remote code execution vulnerability (CVE-2025-1974) with a 9.8 CVSS score exists in Ingress NGINX, affecting over 40% of cloud environments and potentially enabling complete cluster takeover. The vulnerability is unauthenticated, allowing attackers to execute code without credentials. Patch deployment is required to remediate the exposure.
Why it matters: Organizations running Ingress NGINX controllers are at immediate risk of total cluster compromise; this requires urgent patching and assessment of current deployments.
- Source published
- First seen by Cybersecurity Tracker