NVIDIA BlueField Vulnerability Allows Code Execution via Network Messages
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
NVIDIA has disclosed a critical security vulnerability in its BlueField data processing units (DPUs) that enables virtual machine (VM) users to execute arbitrary code through specially crafted network messages. This vulnerability, identified as CVE-2026-65094, affects the VIRTIO-Net implementations on BlueField-3 platforms. The flaw poses a significant risk to cloud and virtualized infrastructure environments, particularly for enterprise deployments. The vulnerability has been assigned a CVSS v3.1 score of 9.0, indicating a high severity level. Organizations using affected systems are urged to take immediate action to mitigate potential exploitation. The exact number of affected systems is not specified, but the impact is expected to be widespread across cloud services utilizing NVIDIA's technology.
Key Points: • CVE-2026-65094 allows arbitrary code execution via crafted network messages. • The vulnerability affects NVIDIA's BlueField-3 DPUs and VIRTIO-Net implementations. • A CVSS score of 9.0 indicates a high risk for enterprise and cloud deployments.