NVIDIA Discloses Critical Vulnerability in BlueField DPUs and ConnectX Platforms
NVIDIA has revealed a high-severity vulnerability (CVE-2026-65094) in its BlueField Data Processing Units (DPUs) and ConnectX networking platforms, which could allow attackers to execute arbitrary code on affected systems. The flaw, rated 9.0 on the CVSS v3.1 scale, resides in the VIRTIO-Net component and stems from a CWE-123 write-what-where condition, enabling malicious actors to manipulate memory by writing data to unintended locations.
The vulnerability is particularly dangerous in multi-tenant and cloud environments, where a low-privileged virtual machine (VM) user could exploit it without user interaction. Successful exploitation could lead to code execution, lateral movement, or disruption of network traffic processing, bypassing traditional security controls. Given that BlueField DPUs are widely used to offload networking, storage, and security tasks in modern data centers, a compromise at this layer poses significant risks to enterprise and cloud deployments.
The issue affects multiple versions of NVIDIA VIRTIO-Net, including:
- GA releases before 25.10.6
- LTS25 before 25.10.2
- LTS24 before 24.10.50
- LTS23 before 23.10.23
NVIDIA has released patched versions and urges organizations to update immediately. While the vulnerability was discovered internally and no active exploitation has been reported, its critical nature combined with the historical exploitation of similar flaws warrants prompt mitigation. Organizations are advised to assess their infrastructure, particularly in environments where untrusted VMs or tenants may access shared networking resources. Updates are available through NVIDIA’s official security portal and DOCA VIRTIO-Net distribution channels.
Source: https://cybersecuritynews.com/nvidia-bluefield-vulnerability/
NVIDIA cybersecurity rating report: https://www.rankiteo.com/company/nvidia
"id": "NVI1785342276",
"linkid": "nvidia",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Enterprises and cloud providers '
'using BlueField DPUs and '
'ConnectX platforms',
'industry': 'Technology/Semiconductors',
'name': 'NVIDIA',
'type': 'Company'}],
'attack_vector': 'Local (low-privileged VM user)',
'customer_advisories': 'Update to patched versions immediately',
'description': 'NVIDIA has revealed a high-severity vulnerability '
'(CVE-2026-65094) in its BlueField Data Processing Units '
'(DPUs) and ConnectX networking platforms, which could allow '
'attackers to execute arbitrary code on affected systems. The '
'flaw, rated 9.0 on the CVSS v3.1 scale, resides in the '
'VIRTIO-Net component and stems from a CWE-123 '
'write-what-where condition, enabling malicious actors to '
'manipulate memory by writing data to unintended locations. '
'The vulnerability is particularly dangerous in multi-tenant '
'and cloud environments, where a low-privileged virtual '
'machine (VM) user could exploit it without user interaction. '
'Successful exploitation could lead to code execution, lateral '
'movement, or disruption of network traffic processing, '
'bypassing traditional security controls.',
'impact': {'operational_impact': 'Code execution, lateral movement, '
'disruption of network traffic processing',
'systems_affected': 'BlueField DPUs and ConnectX networking '
'platforms'},
'investigation_status': 'Vulnerability disclosed, patches released',
'post_incident_analysis': {'corrective_actions': 'Patch released for affected '
'versions',
'root_causes': 'CWE-123 write-what-where condition '
'in VIRTIO-Net component'},
'recommendations': 'Organizations are advised to assess their infrastructure, '
'particularly in environments where untrusted VMs or '
'tenants may access shared networking resources, and apply '
'patches immediately.',
'references': [{'source': 'NVIDIA Security Portal'}],
'response': {'communication_strategy': 'Public disclosure via NVIDIA’s '
'official security portal and DOCA '
'VIRTIO-Net distribution channels',
'containment_measures': 'Patch released for affected versions',
'remediation_measures': 'Update to patched versions (GA '
'25.10.6+, LTS25 25.10.2+, LTS24 '
'24.10.50+, LTS23 23.10.23+)'},
'title': 'NVIDIA Discloses Critical Vulnerability in BlueField DPUs and '
'ConnectX Platforms',
'type': 'Vulnerability',
'vulnerability_exploited': 'CVE-2026-65094 (CWE-123 write-what-where '
'condition)'}