TL;DR
NVIDIA released security updates to fix 14 security flaws in its data center management tooling. These NVIDIA Infrastructure Controller vulnerabilities allow unauthenticated attackers to alter data or escalate privileges on host systems. Administrators must update their Linux installations to version 2.0 to protect their environments.
- Total: 14 CVEs
- Severity: 1 Critical · 5 High · 8 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-65113
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-65113 | 9.8 | CWE-798 | Not exploited |
| CVE-2026-65128 | 8.8 | CWE-89 | Not exploited |
| CVE-2026-65114 | 8.3 | CWE-306 | Not exploited |
| CVE-2026-65121 | 8.2 | CWE-287 | Not exploited |
| CVE-2026-65130 | 8 | CWE-78 | Not exploited |
| CVE-2026-65118 | 7.5 | CWE-295 | Not exploited |
| CVE-2026-65129 | 6.7 | CWE-295 | Not exploited |
| CVE-2026-65125 | 6.6 | CWE-73 | Not exploited |
Why It Matters
NVIDIA Infrastructure Controller manages bare-metal and container hardware across modern AI data centers. Telemetry estimates indicate that hundreds of enterprise clusters rely on this controller software. Therefore, security defects in this management layer create severe risks for computing infrastructure. The most critical flaw, tracked as CVE-2026-65113, earned a CVSS score of 9.8. It allows unauthenticated network actors to compromise target systems completely.
Fortunately, neither active exploitation in the wild nor public proof-of-concept exploit code has been confirmed. The vendor highlighted that “The NVIDIA risk assessment is based on an average of risk across a diverse set of installed systems and may not represent the true risk to your local installation.” Consequently, administrators must evaluate their exposure immediately. Leaving systems unpatched gives attackers a gateway to tamper with sensitive workloads.
How The Attack Works
The security advisory describes several distinct attack mechanisms across the application. The primary defect involves hardcoded credentials within the controller software. In its bulletin, NVIDIA confirmed that “A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.” An unauthenticated attacker over the network uses these static credentials to bypass authentication boundaries.
Additionally, the update addresses a high-severity SQL injection flaw tracked as CVE-2026-65128. Attackers with low privileges can submit crafted database queries to execute arbitrary commands. Other vulnerabilities involve missing authentication on critical functions and command injection in administration scripts. When chained together, these NVIDIA Infrastructure Controller vulnerabilities grant unauthorized actors complete control over the host operating system.
Affected Versions
These security weaknesses affect NVIDIA Infrastructure Controller for Linux versions 0 through 1.9. All earlier branch builds within this release window remain exposed to potential attack. Non-Linux platforms do not run this specific package.
Patch Or Mitigation Steps
Administrators must deploy the latest software release without delay. In the official NVIDIA security advisory, the vendor stated that “NVIDIA has released a software update for NVIDIA Infrastructure Controller.” Operators can clone or update the package directly from the NVIDIA/infra-controller GitHub repository.
Users should upgrade their deployments to version 2.0 or later immediately. Currently, NVIDIA has not provided any temporary workarounds or configuration mitigations. Therefore, installing the official release remains the only viable defense against intrusion. Network teams should also restrict access to internal management interfaces until upgrades finish.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!