NVIDIA has released a security update for its Infrastructure Controller software running on Linux, addressing 14 vulnerabilities that could allow attackers to access sensitive information, execute malicious code, manipulate data, or disrupt affected systems This article explores nvidia released security. . NVIDIA advises organizations to clone or update the software to version 2.0 or later to mitigate all reported issues.
CVE ID Vulnerability CVSS v3.1 Severity CWE CVE-2026-65113 Use of hard-coded credentials 9.8 Critical CWE-798 CVE-2026-65128 SQL injection 8.8 High CWE-89 CVE-2026-65114 Missing authentication for critical function 8.3 High CWE-306 CVE-2026-65121 Improper authentication 8.2 High CWE-287 CVE-2026-65130 OS command injection 8.0 High CWE-78 CVE-2026-65118 Improper certificate validation 7.5 High CWE-295 CVE-2026-65129 Improper certificate validation 6.7 Medium CWE-295 CVE-2026-65125 External control of file name or path 6.6 Medium CWE-73 CVE-2026-65115 Uncontrolled resource consumption 6.5 Medium CWE-400 CVE-2026-65112 Uncontrolled resource consumption 6.5 Medium CWE-400 CVE-2026-65124 XML injection 5.9 Medium CWE-91 CVE-2026-65126 Improper enforcement of behavioral workflow 5.0 Medium CWE-841 CVE-2026-65117 Use of hard-coded password 5.0 Medium CWE-259 CVE-2026-65127 Exposure of sensitive system information through uncleared debug information 4.1 Medium CWE-1258 CVE-2026-65114, rated 8.3, could allow data tampering, denial of service, and information disclosure because a critical function lacked proper authentication.
Organizations should inspect systems running versions 0 through 1.9 of Infrastructure Controller, upgrade to version 2.0 or higher, and review exposed services, access controls, credentials, logs, and network segmentation.




![Top 10 Best Decentralized Identity Solutions in 2026 [Ranked & Scored]](http://cybersecuritynews.com/wp-content/uploads/2026/09/Best-Decentralized-Identity-Solutions-1.webp)






