NVIDIA has released security updates for 14 vulnerabilities in its Infrastructure Controller software for Linux, including one critical and five high-severity flaws. The affected versions are 0 through 1.9; NVIDIA has issued version 2.0 or later as the fix. The controller is used to manage bare-metal and container hardware in data-centre environments. The report says no exploitation in the wild or public proof-of-concept code has been confirmed.
The most serious issue, CVE-2026-65113, has a CVSSv3 score of 9.8 and involves hardcoded credentials. NVIDIA says successful exploitation could enable privilege escalation, data tampering, denial of service and information disclosure. Other issues include CVE-2026-65128, an SQL injection flaw rated 8.8 that can allow low-privileged attackers to execute arbitrary commands, as well as missing authentication and command-injection vulnerabilities.
The report says these weaknesses could potentially be combined to gain control of the host operating system, although it does not provide evidence that such chaining has occurred.
Administrators should upgrade Linux deployments to Infrastructure Controller 2.0 or later using the NVIDIA/infra-controller GitHub repository. NVIDIA has not provided temporary workarounds or configuration mitigations, so applying the update is the stated primary defence. The report also recommends restricting access to internal management interfaces until upgrades are complete.