Blog · Kubernetes
Ingress NGINX, used in about half of cloud native environments, no longer gets patches
In March 2026, Kubernetes retired Ingress NGINX, a component that, according to its own committees, is critical infrastructure for about half of cloud native environments. Since then there have been no new releases and no security fixes. If your cluster still uses it, the next vulnerability won't get a fix.

What happened
On January 29, 2026, the Kubernetes Steering Committee and Security Response Committee published a joint statement. They said the project had needed contributors for years and that, despite its massive use, one or two people maintained it in their spare time. The figure of about half of environments comes from internal Datadog research.
According to the statement, technical debt and some design decisions that make security flaws worse make it impossible to keep maintaining the project, even if resources appeared. Existing deployments keep working, and that's where the risk lies: if you don't check, you may only find out it affects you once you've been compromised.
Why is the risk real?
Datadog Security Labs lays out the history. In March 2025, IngressNightmare (CVE-2025-1974) was disclosed, with a CVSS score of 9.8: it allowed unauthenticated remote code execution and a full takeover of the cluster. On February 2, 2026, four more high-severity vulnerabilities came to light. After March, a flaw like that has no one to fix it.
The CNCF clarifies a point that often gets mixed up: the Kubernetes Ingress API is still supported. What was retired is the ingress-nginx controller that the community maintained.
How to move off it
The statement warns that no alternative is a drop-in replacement and that migrating takes planning and engineering hours. The CNCF describes two paths. One is to keep your Ingress resources and swap the controller for another one, such as Contour; the cost is that nginx.ingress.kubernetes.io/* annotations stop working. The other is to move to Gateway API, the successor to Ingress, using the ingress2gateway tool to automate the translation.