CVE-2025-1974Patch

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-653

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Peaked 3d ago at 1 mentions (2026-02-10); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-20: 1Mentions · 2026-03-25: 1Mentions · 2026-04-16: 1PoC Mentioned / Linked · 2026-02-10: 1Exploit Tool / Code · 2026-02-10: 1Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-20: 1Technical Details · 2026-03-25: 1Technical Details · 2026-04-16: 102-1002-2003-2504-16
Signal classification3 categories
Patch
250.0%
PoC
125.0%
Exploit
125.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-101
PoC1
2026-02-201
Exploit1
2026-03-251
Patch1
2026-04-161
Patch1
Full discourse4 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2025-1974: Kubernetes IngressNightmare Vulnerability CVSS: 9.8 PoC: https://github.com/hakaioffsec/IngressNightmare-PoC PoC Published: March 26th, 2026 https://t.co/H4WR4S5snt

    Post summary

    A PoC for CVE‑2025‑1974 (Kubernetes IngressNightmare) has been published with a GitHub repo link, but no evidence of active exploitation, patches, or false positives.

    73801608015.7K
    164.8K followersView on X
  • Yoko Hasebe (長谷部洋子 岩国市)@yokotf4yur
    Patch

    https://youtube.com/shorts/6BSWMZkihUI?si=YmepQEcWwfKlNBnJ ## ✅ 確認済み:最新 Azure 脆弱性・CVE 情報(2025〜2026年) ### 🔴 最重要:CVE-2025-55241(Entra ID) **CVSS 10.0 / Critical** Microsoft Entra IDのトークン検証不備により、攻撃者が任意のユーザー(グローバル管理者を含む)をすべてのテナントにわたって偽装できる脆弱性。発見者はセキュリティ研究者 Dirk-Jan Mollema(2025年7月14日報告)で、Microsoftは3日後の7月17日に修正を完了。顧客側の対応は不要。野生での悪用は確認されていない。 [The Hacker News](https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html) 技術的な原因は、レガシーAzure AD Graph APIのトークン検証の欠陥。攻撃者が自テナントで取得した「Actorトークン」を他テナントに使い回すことで、MFAや条件付きアクセスポリシーをバイパスしてテナント全体を侵害できる状態だった。 [Uvcyber](https://www.uvcyber.com/resources/reports/threat-advisory-azure-entra-id-vulnerability) **対応アクション:** - Azure AD Graph API(2025年8月31日に廃止済み)への依存を排除 - Microsoft Graphへ移行 - PIM(Privileged Identity Management)の導入 --- ### 🔴 CVE-2026-20965(Windows Admin Center) **High / テナント全体への横断アクセス** Windows Admin Center の Azure SSO実装に高深刻度の脆弱性。不正なトークン検証により、Azure VMおよびArc接続システム全体への不正アクセスが可能。Microsoftは2026年1月13日リリースのv0.70.00で修正。それ以前のバージョンは依然として脆弱。 [Gopher](https://www.gopher.security/news/critical-azure-entra-id-vulnerability-allows-tenant-wide-compromise) --- ### 🟠 AKS(Azure Kubernetes Service)関連 CVE 2025年3月、Kubernetes nginx ingress controllerに複数の脆弱性が開示された:CVE-2025-1974(Critical)、CVE-2025-1098(High)、CVE-2025-1097(High)、CVE-2025-24514(High)、CVE-2025-24513(Medium)。ingress-nginxを使用しているクラスターが対象。AKSのマネージドアドオンはパッチ済みだが、独自導入の場合はv1.11.5またはv1.12.1へのアップデートが必要。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) また、runcに関するCVE-2025-31133、CVE-2025-52565、CVE-2025-52881も開示済み。新しいノードイメージがロールアウトされている。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) --- ### 🟠 Azure Bastion CVE-2025-49752 **CVSS 10.0 / Critical** Azure BastionにCVE-2025-49752として追跡される重大な認証バイパス脆弱性。単一のネットワークリクエストでAzure VMへの管理者アクセスを取得できる可能性がある。CWE-294(認証バイパス)に分類され、事前認証・ユーザー操作なしでリモート悪用が可能。 [Zeropath](https://zeropath.com/blog/azure-bastion-cve-2025-49752) --- ### 🟡 2026年4月 Patch Tuesday(最新・4月16日) Microsoftは2026年4月のPatch Tuesdayで163件のCVEを修正。うち8件がCritical評価。CVE-2026-32201はSharePointのゼロデイで実際に悪用された。 [Tenable®](https://www.tenable.com/blog/microsofts-april-2026-patch-tuesday-addresses-163-cves-cve-2026-32201) 主なCVE: - **CVE-2026-33826**:Windows Active Directory RCE(Critical、CVSS 8.0) - **CVE-2026-33824**:Windows IKE RCE(Critical、CVSS 9.8、未認証攻撃可能) - **CVE-2026-33825**:Microsoft Defender 権限昇格(Important) --- ### 📋 信頼性まとめ | CVE | サービス | 深刻度 | 確認状況 | |-----|---------|--------|---------| | CVE-2025-55241 | Entra ID | CVSS 10.0 | ✅ 実在 | | CVE-2025-49752 | Azure Bastion | CVSS 10.0 | ✅ 実在 | | CVE-2026-20965 | Windows Admin Center | High | ✅ 実在 | | CVE-2025-1974 | AKS nginx | Critical | ✅ 実在 | | CVE-2026-32201 | SharePoint | 実悪用確認 | ✅ 実在 | --- 特定のCVEの詳細や、対策方法について知りたい場合はお知らせください!←Claude

    Post summary

    This post is an informational overview of several recent Azure VM and related CVEs, detailing guaranteed fixes, vendor advisories, and mitigation steps, while noting that CVE‑2026‑32201 has already been actively exploited.

    00000231
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Kubernetes archives ingress-nginx at KubeCon 2026, ending security patches for CVE-2025-1974 RCE risk impacting 43% of cloud environments. https://threatcluster.io/cluster/kubernetes-archives-ingress-nginx-amid-security-concerns-255c8540

    Post summary

    Kubernetes announced that it will archive ingress‑nginx at KubeCon 2026, effectively ceasing security patches for CVE-2025-1974 RCE, a vulnerability that impacts roughly 43% of cloud environments.

    00000192
    114 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Exploit

    Kubernetes to retire Ingress NGINX after March 2026, ending all fixes and security updates. The March 2025 “IngressNightmare” RCE (CVE-2025-1974) exploited critical flaws with CVSS 9.8 severity. #IngressNGINX #Kubernetes #RCE https://ift.tt/pCjzhmH

    Post summary

    Kubernetes announced the retirement of Ingress NGINX after March 2026, highlighting the high-severity RCE CVE-2025-1974 with CVSS 9.8, but offers no patch or PoC.

    00000115
    3.6K followersView on X

Explore more