Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2025-1097] IngressNightmare: CVE-2025-1974 - 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX

Summary

Wiz Research discovered IngressNightmare: four unauthenticated RCE flaws in Kubernetes Ingress NGINX (CVE-2025-1974 et al., CVSS 9.8) exposing all cluster secrets; ~43% of cloud environments affected.
Published
Collected

original ↗

Related coverage

back