← Front PageVulnerabilities Desk
Vulnerabilities
IngressNightmare: CVE-2025-1974 - 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX
CVE-2025-1974 enables unauthenticated cluster takeover in 40% of Kubernetes environments running Ingress NGINX.
Summary written by editorial AI · Source link below
CVSS9.8criticalCVE-2025-1974
Over 40% of cloud environments are vulnerable to RCE, likely leading to a complete cluster takeover.
Continue at the source
Read the full report at Wiz BlogExternal link — opens at Wiz Blog in a new tab.
§
Continue with
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d