NVIDIA BlueField Vulnerability Allows Code Execution via Network Messages
Article Content
- •CVE-2026-65094 allows arbitrary code execution via crafted network messages.
- •The vulnerability affects NVIDIA's BlueField-3 DPUs and VIRTIO-Net implementations.
- •A CVSS score of 9.0 indicates a high risk for enterprise and cloud deployments.
NVIDIA has disclosed a critical security vulnerability in its BlueField data processing units (DPUs) that enables virtual machine (VM) users to execute arbitrary code through specially crafted network messages. This vulnerability, identified as CVE-2026-65094, affects the VIRTIO-Net implementations on BlueField-3 platforms. The flaw poses a significant risk to cloud and virtualized infrastructure environments, particularly for enterprise deployments. The vulnerability has been assigned a CVSS v3.1 score of 9.0, indicating a high severity level. Organizations using affected systems are urged to take immediate action to mitigate potential exploitation. The exact number of affected systems is not specified, but the impact is expected to be widespread across cloud services utilizing NVIDIA's technology.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Nvidia and CVE-2026-65094 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…