NVIDIA Infrastructure Controller for Linux: 14 Vulnerabilities Disclosed Together, Ranging to Critical
NVIDIA addressed a critical batch of 14 vulnerabilities in its Infrastructure Controller for Linux, disclosed on September 22, 2026, with risks including code execution and privilege escalation.

Key findings
- NVIDIA Infrastructure Controller for Linux patched against 14 vulnerabilities disclosed on September 22, 2026.
- Critical flaw CVE-2026-65113 involves hard-coded credentials, leading to privilege escalation and data tampering.
- Vulnerabilities include OS command injection (CVE-2026-65130), SQL injection (CVE-2026-65128), and improper certificate validation (CVE-2026-65129).
- Affected versions are 0 through 1.9; update to 2.0 or later is recommended.
- Risks range from information disclosure and data tampering to code execution and denial of service.
On September 22, 2026, NVIDIA disclosed a batch of 14 vulnerabilities affecting its Infrastructure Controller for Linux. These vulnerabilities, all disclosed on the same day, range in severity from medium to critical, with the most severe flaw carrying a CVSS score of 9.8. The disclosures highlight potential risks including OS command injection, SQL injection, improper certificate validation, and the use of hard-coded credentials, which could lead to code execution, data tampering, denial of service, and information disclosure.
The vulnerabilities can be grouped by their impact and attack vector:
Command and Injection Flaws
Several vulnerabilities allow for code or command injection. CVE-2026-65130, a high-severity flaw, enables OS command injection, potentially leading to code execution and other impacts. Similarly, CVE-2026-65128, a high-severity vulnerability, involves SQL injection, with similar potential consequences. CVE-2026-65124, a medium-severity XML injection vulnerability, could result in data tampering and denial of service. Additionally, CVE-2026-65111, affecting NVIDIA NeMo Speech, is a code injection vulnerability.
Authentication and Authorization Issues
Improper authentication and certificate validation are also present. CVE-2026-65121, a high-severity vulnerability, stems from an improper authentication issue, potentially leading to privilege escalation. CVE-2026-65129 and CVE-2026-65118 both involve improper certificate validation, which could result in information disclosure, data tampering, and denial of service.
Hard-coded Credentials and Resource Management
The batch includes vulnerabilities related to hard-coded credentials and resource consumption. CVE-2026-65113, a critical vulnerability with a CVSS score of 9.8, involves the use of hard-coded credentials, posing a significant risk of privilege escalation, data tampering, denial of service, and information disclosure. CVE-2026-65117 and CVE-2026-65115 describe uncontrolled resource consumption, leading to denial of service. CVE-2026-65117 specifically has a CVSS score of 6.5.
Other Vulnerabilities
Other disclosed issues include CVE-2026-65126, which involves external control of a file name or path, potentially leading to code execution and privilege escalation. CVE-2026-65125 concerns improper enforcement of a behavioral workflow, and CVE-2026-65127, a medium-severity flaw, is due to uncleared debug information, leading to exposure of sensitive system information. CVE-2026-65117 involves the use of a hard-coded password.
NVIDIA addressed these vulnerabilities in their September 2026 Infrastructure Controller security bulletin. The update, version 2.0 or later, resolves all 14 disclosed issues. Affected versions range from 0 through 1.9. Users are strongly recommended to update to version 2.0 or higher to mitigate the risks associated with these flaws.
This coordinated disclosure of 14 vulnerabilities underscores the importance of timely patching for NVIDIA Infrastructure Controller for Linux users. The range of severities and attack vectors highlights the need for a comprehensive security review and prompt application of updates to protect against potential code execution, data breaches, and service disruptions.
Cyber Security News reported on this disclosure, noting that the vulnerabilities could allow attackers to access sensitive system information, execute code, alter data, or disrupt affected environments. The report specifically mentioned CVE-2026-65127 as a medium-severity vulnerability related to uncleared debug information. Cyber Security News