Security
Headlines
HeadlinesLatestCVEs

Headline

Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication

A set of five critical security shortcomings have been disclosed in the Ingress NGINX Controller for Kubernetes that could result in unauthenticated remote code execution, putting over 6,500 clusters at immediate risk by exposing the component to the public internet. The vulnerabilities (CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, and CVE-2025-1974 ), assigned a CVSS score of

The Hacker News
#vulnerability#kubernetes#rce#nginx#auth#The Hacker News

The Hacker News: Latest News

RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer