Skip to content
ThreatCluster

NVIDIA BlueField Vulnerability Allows Code Execution via Network Messages

First seen 29 Jul 2026, 21:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 18:52 UTC
  • CVE-2026-65094 allows arbitrary code execution via crafted network messages.
  • The vulnerability affects NVIDIA's BlueField-3 DPUs and VIRTIO-Net implementations.
  • A CVSS score of 9.0 indicates a high risk for enterprise and cloud deployments.

NVIDIA has disclosed a critical security vulnerability in its BlueField data processing units (DPUs) that enables virtual machine (VM) users to execute arbitrary code through specially crafted network messages. This vulnerability, identified as CVE-2026-65094, affects the VIRTIO-Net implementations on BlueField-3 platforms. The flaw poses a significant risk to cloud and virtualized infrastructure environments, particularly for enterprise deployments. The vulnerability has been assigned a CVSS v3.1 score of 9.0, indicating a high severity level. Organizations using affected systems are urged to take immediate action to mitigate potential exploitation. The exact number of affected systems is not specified, but the impact is expected to be widespread across cloud services utilizing NVIDIA's technology.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 53d ago How this analysis works

Timeline

2026-07-29
NVIDIA discloses BlueField vulnerability
NVIDIA announced a critical vulnerability in BlueField DPUs that allows code execution through crafted messages, impacting cloud and virtualized environments.
Gbhackers
2026-07-29
CVE-2026-65094 assigned
The vulnerability affecting NVIDIA's VIRTIO-Net component was tracked as CVE-2026-65094 with a CVSS score of 9.0.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track Nvidia and CVE-2026-65094 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed