CVE-2025-24514Active Exploitation

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-02-02); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-02: 1Mentions · 2026-04-16: 1PoC Mentioned / Linked · 2026-02-02: 1Active Exploitation · 2026-02-02: 1Active Exploitation · 2026-04-16: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-02-02: 1Technical Details · 2026-04-16: 102-0204-16
Signal classification2 categories
Active Exploitation
150.0%
Patch
150.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-021
Active Exploitation1
2026-04-161
Patch1
Full discourse2 posts
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2025-24514 : CRITICAL KUBERNETES RCE ALERT 🚨 A critical unauthenticated remote code execution vulnerability has been disclosed in ingress-nginx, exploitable via malicious injection in the `http://nginx.ingress.kubernetes.io/auth-url` annotation. A single crafted Ingress resource can lead to full cluster compromise. Risk Severity: - Critical (CVSS 10.0, active exploitation, public proof-of-concept available, trending) Impact: - Unauthenticated remote code execution in ingress-nginx controller - Cluster-wide Secret disclosure (tokens, DB creds, TLS certs, cloud API keys) - Complete breakdown of multi-tenant isolation - Ingress traffic interception and manipulation - Lateral movement across all namespaces - Persistent backdoors at the control-plane edge Root Cause: - CWE-94 (Improper Control of Generation of Code). The ingress-nginx controller fails to properly validate and sanitize user-supplied values in the `auth-url` annotation, allowing malicious configuration directives to be injected into the generated NGINX configuration and executed during reload. Attackers can: - Inject malicious directives via a crafted Ingress annotation - Trigger NGINX config reloads leading to command execution - Gain RCE inside the privileged controller pod - Enumerate and exfiltrate Secrets across all namespaces - Intercept, modify, or reroute all ingress traffic - Establish persistence by backdooring ingress routes or controller configs Are You Affected? - Vulnerable: Ingress-nginx deployments with the current auth-url annotation parser - Scope: Multi-tenant clusters, CI/CD environments, managed Kubernetes services, and any cluster where users can create or modify Ingress resources Immediate Action Required: - Update: Monitor the ingress-nginx GitHub repository and upgrade immediately once the emergency patch is released - Mitigation: Restrict Ingress creation via RBAC, block `http://nginx.ingress.kubernetes.io/auth-url` annotations using OPA Gatekeeper or Kyverno, and isolate controller pods with strict network policies - Audit: Hunt for auth-url annotations across all namespaces, monitor controller logs for abnormal reloads, and alert on unexpected outbound traffic from ingress-nginx pods Ingress controllers sit at the blast radius edge of every cluster. Treat this as a cluster-wide incident, not a namespace issue. 🛡️ #ostorlabCVE

    Post summary

    CVE-2025-24514 is a critical unauthenticated RCE in ingress‑nginx via the auth‑url annotation, with active exploitation reported, a public PoC available, and urgent patch/mitigation steps advised.

    01031372
    582 followersView on X
  • Yoko Hasebe (長谷部洋子 岩国市)@yokotf4yur
    Patch

    https://youtube.com/shorts/6BSWMZkihUI?si=YmepQEcWwfKlNBnJ ## ✅ 確認済み:最新 Azure 脆弱性・CVE 情報(2025〜2026年) ### 🔴 最重要:CVE-2025-55241(Entra ID) **CVSS 10.0 / Critical** Microsoft Entra IDのトークン検証不備により、攻撃者が任意のユーザー(グローバル管理者を含む)をすべてのテナントにわたって偽装できる脆弱性。発見者はセキュリティ研究者 Dirk-Jan Mollema(2025年7月14日報告)で、Microsoftは3日後の7月17日に修正を完了。顧客側の対応は不要。野生での悪用は確認されていない。 [The Hacker News](https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html) 技術的な原因は、レガシーAzure AD Graph APIのトークン検証の欠陥。攻撃者が自テナントで取得した「Actorトークン」を他テナントに使い回すことで、MFAや条件付きアクセスポリシーをバイパスしてテナント全体を侵害できる状態だった。 [Uvcyber](https://www.uvcyber.com/resources/reports/threat-advisory-azure-entra-id-vulnerability) **対応アクション:** - Azure AD Graph API(2025年8月31日に廃止済み)への依存を排除 - Microsoft Graphへ移行 - PIM(Privileged Identity Management)の導入 --- ### 🔴 CVE-2026-20965(Windows Admin Center) **High / テナント全体への横断アクセス** Windows Admin Center の Azure SSO実装に高深刻度の脆弱性。不正なトークン検証により、Azure VMおよびArc接続システム全体への不正アクセスが可能。Microsoftは2026年1月13日リリースのv0.70.00で修正。それ以前のバージョンは依然として脆弱。 [Gopher](https://www.gopher.security/news/critical-azure-entra-id-vulnerability-allows-tenant-wide-compromise) --- ### 🟠 AKS(Azure Kubernetes Service)関連 CVE 2025年3月、Kubernetes nginx ingress controllerに複数の脆弱性が開示された:CVE-2025-1974(Critical)、CVE-2025-1098(High)、CVE-2025-1097(High)、CVE-2025-24514(High)、CVE-2025-24513(Medium)。ingress-nginxを使用しているクラスターが対象。AKSのマネージドアドオンはパッチ済みだが、独自導入の場合はv1.11.5またはv1.12.1へのアップデートが必要。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) また、runcに関するCVE-2025-31133、CVE-2025-52565、CVE-2025-52881も開示済み。新しいノードイメージがロールアウトされている。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) --- ### 🟠 Azure Bastion CVE-2025-49752 **CVSS 10.0 / Critical** Azure BastionにCVE-2025-49752として追跡される重大な認証バイパス脆弱性。単一のネットワークリクエストでAzure VMへの管理者アクセスを取得できる可能性がある。CWE-294(認証バイパス)に分類され、事前認証・ユーザー操作なしでリモート悪用が可能。 [Zeropath](https://zeropath.com/blog/azure-bastion-cve-2025-49752) --- ### 🟡 2026年4月 Patch Tuesday(最新・4月16日) Microsoftは2026年4月のPatch Tuesdayで163件のCVEを修正。うち8件がCritical評価。CVE-2026-32201はSharePointのゼロデイで実際に悪用された。 [Tenable®](https://www.tenable.com/blog/microsofts-april-2026-patch-tuesday-addresses-163-cves-cve-2026-32201) 主なCVE: - **CVE-2026-33826**:Windows Active Directory RCE(Critical、CVSS 8.0) - **CVE-2026-33824**:Windows IKE RCE(Critical、CVSS 9.8、未認証攻撃可能) - **CVE-2026-33825**:Microsoft Defender 権限昇格(Important) --- ### 📋 信頼性まとめ | CVE | サービス | 深刻度 | 確認状況 | |-----|---------|--------|---------| | CVE-2025-55241 | Entra ID | CVSS 10.0 | ✅ 実在 | | CVE-2025-49752 | Azure Bastion | CVSS 10.0 | ✅ 実在 | | CVE-2026-20965 | Windows Admin Center | High | ✅ 実在 | | CVE-2025-1974 | AKS nginx | Critical | ✅ 実在 | | CVE-2026-32201 | SharePoint | 実悪用確認 | ✅ 実在 | --- 特定のCVEの詳細や、対策方法について知りたい場合はお知らせください!←Claude

    Post summary

    The text summarizes multiple Azure and Windows CVEs, detailing their severity, exploitation status, and patch/update status, with only CVE-2026-32201 reported as actively exploited.

    00000231

Explore more