Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI Phishing Steals Browser Sessions Without Malware
July 29, 2026
macOS ClickFix Vulnerability Exploited to Deploy Atomic Stealer
July 29, 2026
Critical NVIDIA BlueField Vulner2 Vulnerability Allows Code Execution
July 29, 2026
Home/CyberSecurity News/Critical NVIDIA BlueField Vulner2 Vulnerability Allows Code Execution
CyberSecurity News

Critical NVIDIA BlueField Vulner2 Vulnerability Allows Code Execution

Key Takeaways A critical vulnerability (CVE-2026-65094) has been identified in NVIDIA BlueField DPUs and ConnectX networking platforms. The flaw, a “write-what-where” issue in the...

Emy Elsamnoudy
Emy Elsamnoudy
July 29, 2026 3 Min Read
2 0

Key Takeaways

  • A critical vulnerability (CVE-2026-65094) has been identified in NVIDIA BlueField DPUs and ConnectX networking platforms.
  • The flaw, a “write-what-where” issue in the VIRTIO-Net component, carries a CVSS v3.1 score of 9.0, indicating high severity.
  • Successful exploitation allows low-privileged virtual machine users to execute arbitrary code, particularly dangerous in multi-tenant cloud environments.
  • NVIDIA has released patched versions and urges immediate updates to prevent potential compromise.

NVIDIA Discloses Critical Code Execution Flaw in BlueField DPUs and ConnectX Platforms

NVIDIA has announced a severe security vulnerability impacting its BlueField Data Processing Units (DPUs) and ConnectX networking products. This flaw, if successfully exploited, could enable attackers to execute arbitrary code on affected systems, posing a significant risk to enterprise and cloud infrastructure.

Table Of Content

  • Key Takeaways
  • NVIDIA Discloses Critical Code Execution Flaw in BlueField DPUs and ConnectX Platforms
  • Vulnerability Details: CVE-2026-65094
  • Attack Scenario and Impact
  • Affected Versions and Patch Availability
  • What You Should Do

Vulnerability Details: CVE-2026-65094

Designated as CVE-2026-65094, the vulnerability resides within the VIRTIO-Net component and has been assigned a CVSS v3.1 base score of 9.0. This score underscores the critical nature of the issue, which could have far-reaching implications for organizations utilizing NVIDIA’s high-performance networking solutions.

According to NVIDIA’s security bulletin released in July 2026, the BlueField-3 Virtio-Net implementation is susceptible to a CWE-123 “write-what-where” vulnerability. This class of flaw allows a malicious actor to write arbitrary data to any memory location, effectively enabling memory manipulation. Such capabilities are particularly dangerous as they can be leveraged to inject and execute attacker-controlled code, potentially compromising the system’s integrity and confidentiality.

Attack Scenario and Impact

The attack vector for CVE-2026-65094 involves a low-privileged user within a virtual machine (VM) crafting a specific malicious message. This crafted message is designed to trigger the vulnerability without requiring any user interaction. Given that the attack is “adjacent,” it poses a substantial threat in shared or multi-tenant environments, such as those found in cloud infrastructures and virtualized data centers.

Furthermore, NVIDIA notes that the vulnerability involves a scope change. This means that successful exploitation could impact resources beyond the initially compromised component, significantly increasing the potential blast radius in production environments. BlueField DPUs are integral to modern data centers, offloading critical networking, storage, and security functions from host CPUs. A compromise at this foundational layer could allow attackers to bypass established security controls, facilitate lateral movement across workloads, or disrupt essential network traffic processing. This heightened risk profile is particularly relevant for organizations heavily dependent on NVIDIA networking solutions for high-performance computing and cloud-native applications.

Affected Versions and Patch Availability

The vulnerability impacts numerous versions of NVIDIA VIRTIO-Net across both general availability (GA) and long-term support (LTS) releases. Specifically, all versions prior to 25.10.6 for VIRTIO-Net GA, 25.10.2 for LTS25, 24.10.50 for LTS24, and 23.10.23 for LTS23 are affected.

NVIDIA has released patched versions to address this critical flaw and strongly advises organizations to update their systems immediately to mitigate potential exploitation. While NVIDIA’s risk assessment provides a general overview, the company emphasizes that specific environmental factors might influence actual exposure levels. Organizations are encouraged to conduct their own evaluations, especially where untrusted virtual machines or tenants might access shared networking resources. The vulnerability was discovered internally by NVIDIA, and as of the disclosure date, no active exploitation has been reported in the wild. However, given the severe nature of “write-what-where” vulnerabilities, security teams should prioritize patching this issue without delay.

What You Should Do

  • Apply Patches Immediately: Update all affected NVIDIA BlueField DPUs and ConnectX networking platforms to the latest patched versions provided by NVIDIA.
  • Restrict Access: Limit access for untrusted virtual machines or tenants to shared networking resources where feasible.
  • Monitor Network Behavior: Implement and enhance monitoring for unusual network activity or anomalous behavior within your infrastructure.
  • Review Infrastructure: Conduct a thorough review of your environment, particularly configurations involving virtualized data centers and cloud deployments, to understand specific exposure levels.
  • Layered Defense: Maintain a robust, layered security strategy that incorporates patch management, access controls, and continuous monitoring to reduce overall risk.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Russian APT28 Phishes Signal Backup Keys to Hijack Accounts

Next Post

macOS ClickFix Vulnerability Exploited to Deploy Atomic Stealer

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Flaw in Joyfill npm Packages Lets Attackers Deploy RAT and Steal Credentials
July 29, 2026
Critical Tor Browser Bug Lets Attackers Hijack Users
July 29, 2026
Russia Charges Telegram CEO Pavel Durov With Aiding Terrorism
July 29, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us