Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems

Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems

Posted on July 29, 2026 By CWS

NVIDIA has recently revealed a significant security flaw in its BlueField Data Processing Units (DPUs) and ConnectX networking platforms. This flaw, if exploited, could allow malicious actors to execute unauthorized code, posing a severe threat to affected systems.

High-Risk Vulnerability Details

Identified as CVE-2026-65094, this vulnerability affects the VIRTIO-Net component and has been assigned a CVSS v3.1 score of 9.0. This rating highlights its high-risk potential, particularly concerning enterprise and cloud environments. According to a July 2026 security bulletin from NVIDIA, the BlueField-3 Virtio-Net contains a CWE-123 write-what-where vulnerability, which permits attackers to manipulate memory by writing arbitrary data to unintended locations.

Such vulnerabilities are particularly alarming as they can lead to the execution of attacker-controlled code, thereby threatening the integrity and confidentiality of the systems involved.

Attack Scenarios and Implications

The primary attack scenario involves a low-privilege virtual machine (VM) user crafting a malicious payload to exploit this vulnerability. Because the attack vector is adjacent and requires no user interaction, it poses a significant threat to shared or multi-tenant environments, like cloud infrastructures and virtualized data centers.

Moreover, the vulnerability includes a scope change, allowing exploitation to extend beyond the initially compromised component. This amplifies its severity in production settings, where BlueField DPUs handle critical networking, storage, and security tasks. A breach at this level could allow attackers to bypass traditional security measures, move laterally within networks, or disrupt traffic processing.

Versions Affected and Mitigation Steps

The vulnerability impacts multiple VIRTIO-Net versions, including general availability and long-term support releases. Specifically, it affects all versions before 25.10.6 for GA, 25.10.2 for LTS25, 24.10.50 for LTS24, and 23.10.23 for LTS23. NVIDIA has issued patched versions to address this issue and strongly advises organizations to update immediately to prevent potential exploitation.

Although no active exploitation has been reported as of the disclosure date, the company underscores the importance of assessing infrastructure vulnerabilities, particularly when untrusted VMs or tenants have access to shared resources. The risk assessment is an average and may not fully capture specific exposure levels across various environments.

Organizations are urged to secure their systems by applying available patches, restricting access to untrusted VMs, and monitoring abnormal network activities as part of a comprehensive defense strategy. Updates are available through NVIDIA’s product security portal and DOCA VIRTIO-Net distribution channels.

This incident underscores the critical nature of addressing write-what-where vulnerabilities promptly, given their history of exploitation in real-world scenarios.

Cyber Security News Tags:BlueField, cloud security, code execution, CVE-2026-65094, Cybersecurity, data center, DPU, enterprise security, Networking, Nvidia, patch update, security risk, Virtio-Net, Vulnerability

Post navigation

Previous Post: OpenAI Models Exploit JFrog Zero-Day in Major Hack
Next Post: VMware Security Flaws: Auth Bypass and Code Execution Risks

Related Posts

New Malware Loader ‘CountLoader’ Weaponized PDF File to Deliver Ransomware New Malware Loader ‘CountLoader’ Weaponized PDF File to Deliver Ransomware Cyber Security News
Phishing Alert Targets LastPass Users for Vault Access Phishing Alert Targets LastPass Users for Vault Access Cyber Security News
Why Threat Prioritization Is the Key SOC Performance Driver   Why Threat Prioritization Is the Key SOC Performance Driver   Cyber Security News
Criminal IP and Palo Alto Networks Cortex XSOAR Integrate to Deliver AI-Driven Exposure Intelligence Criminal IP and Palo Alto Networks Cortex XSOAR Integrate to Deliver AI-Driven Exposure Intelligence Cyber Security News
New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware Cyber Security News
Threat Actors Behind WARMCOOKIE Malware Added New Features to It’s Arsenal Threat Actors Behind WARMCOOKIE Malware Added New Features to It’s Arsenal Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Phishing Threatens Browser Security
  • Critical Rails Vulnerability Allows File Access via Image Uploads
  • Mac Users Threatened by ClickFix Campaign with Atomic Stealer
  • VMware Security Flaws: Auth Bypass and Code Execution Risks
  • Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Phishing Threatens Browser Security
  • Critical Rails Vulnerability Allows File Access via Image Uploads
  • Mac Users Threatened by ClickFix Campaign with Atomic Stealer
  • VMware Security Flaws: Auth Bypass and Code Execution Risks
  • Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark