Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Critical Vulnerabilities Threaten 40% of Kubernetes Deployments
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Critical Vulnerabilities Threaten 40% of Kubernetes Deployments

Highlights

  • Ingress Nginx Controller vulnerabilities risk 43% of cloud environments.

  • Critical flaw CVE-2025-1974 has a CVSS score of 9.8.

  • Immediate patching and monitoring are essential to prevent exploits.

Kaan Demirel
Last updated: 26 March, 2025 - 7:29 pm 7:29 pm
Kaan Demirel 2 months ago
Share
SHARE

A significant security alert has emerged for Kubernetes environments, as multiple vulnerabilities discovered in the Ingress Nginx Controller put a substantial portion of cloud infrastructures at risk. These flaws could potentially allow unauthorized access and control over numerous cloud-based applications. Organizations utilizing Kubernetes are urged to immediately assess their systems to prevent possible exploitations.

Contents
What are the newly discovered vulnerabilities in Ingress Nginx?How can these vulnerabilities impact Kubernetes clusters?What steps should administrators take to mitigate the risks?

Similar security incidents in the past have highlighted the critical importance of timely patch management. Previous vulnerabilities in widely-used Kubernetes components have also led to widespread threats, emphasizing the need for continuous security monitoring and prompt response to identified risks. This latest discovery underscores the persistent challenges in safeguarding cloud environments.

What are the newly discovered vulnerabilities in Ingress Nginx?

Wiz researchers identified five vulnerabilities in the Ingress Nginx Controller, with CVE-2025-1974 being the most severe, rated 9.8 on CVSS. These defects include unauthenticated remote code execution and high-severity configuration injection flaws.

“The exploit chain is unauthenticated and a target is vulnerable in a default configuration,”

stated Stephen Fewer of Rapid7, highlighting the ease of exploitation.

How can these vulnerabilities impact Kubernetes clusters?

Exploitation could grant attackers access to cluster-wide secrets or full control over the cluster, potentially compromising sensitive data and operations. With over 43% of cloud environments and more than 6,500 Kubernetes clusters at risk, the widespread use heightens the threat level. According to Tabitha Sable,

“CVE-2025-1974 means that anything on the pod network has a good chance of taking over your Kubernetes cluster.”

What steps should administrators take to mitigate the risks?

Administrators are advised to promptly apply the released patches for all five vulnerabilities to secure exposed Ingress Nginx Controllers. Additionally, monitoring for publicly exposed and vulnerable hosts can prevent potential exploits, as evidenced by approximately 5,000 at-risk hosts identified by Censys scans.

“With exploit code for CVE-2025-1974 starting to be published online, Kubernetes administrators should remediate publicly-exposed instances on an urgent basis,”

Fewer emphasized.

Security teams must prioritize patch management and continuous monitoring within Kubernetes environments to mitigate such vulnerabilities. The prevalence of Ingress Nginx Controllers across numerous deployments makes prompt action essential to protect against unauthorized access and potential cluster takeovers. Implementing robust security protocols and staying informed about emerging threats will be crucial for maintaining the integrity of cloud infrastructures.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

DHS Faces Scrutiny for Withholding CISA Workforce Details

MITRE’s CVE Program Faces Funding Shake-up and Future Alternatives

Microsoft Tackles 72 Vulnerabilities in May Security Update

Apple Boosts Security With Extensive Software Updates

US Authorities Dismantle Botnets and Indict Foreign Nationals

Share This Article
Facebook Twitter Copy Link Print
Kaan Demirel
By Kaan Demirel
Kaan Demirel is a 28-year-old gaming enthusiast residing in Ankara. After graduating from the Statistics department of METU, he completed his master's degree in computer science. Kaan has a particular interest in strategy and simulation games and spends his free time playing competitive games and continuously learning new things about technology and game development. He is also interested in electric vehicles and cyber security. He works as a content editor at NewsLinker, where he leverages his passion for technology and gaming.
Previous Article Publishers Scramble to Avoid GTA 6 Release Clashes
Next Article Japanese Game Publishers Thrive as Western Studios Struggle

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Intel Excites GPU Enthusiasts with Hint at New Arc B770 Launch
Computing
Tesla VP Shares Insight Into Stunning Robot Dance
Electric Vehicle
US Stops AI Rule, Tightens Chip Export Measures
AI
Tesla Cybertrucks Join Trump’s Motorcade in Qatar
Electric Vehicle
Upcoming NVIDIA RTX 5060 Pricing Leaked Ahead of Launch
Computing
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?