Threat reportVulnerabilityTL-2026-1812

CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Execution

criticalPATCHED

CVE-2026-65094 (TL-2026-1812) is a critical-severity software vulnerability scored CVSS 9, first published 2026-08-01. It has no confirmed attribution, affects NVIDIA BlueField-3 DPU / ConnectX VIRTIO-Net (GA), references 1 CVE (CVE-2026-65094), maps to 14 MITRE ATT&CK techniques (T1005, T1014, T1040), and is covered by 9 detection rules and 23 indicators of compromise.

CVSS
9/10Critical
CVEs
1Referenced vulnerabilities
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-1812

Threat ID
TL-2026-1812
Severity
CRITICAL
CVSS
9 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
cloudserviceproviders, datacenteroperators, highperformancecomputing, telecoms, technologysemiconductor
Target regions
Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in CVE-2026-65094

Malware and tooling: NVIDIA DOCA SDK

How CVE-2026-65094 works

A CWE-123 write-what-where vulnerability (CVE-2026-65094, CVSS 9.0) in the VIRTIO-Net implementation on NVIDIA BlueField-3 DPUs and ConnectX networking platforms lets a low-privileged virtual machine user craft a malicious message to write arbitrary data to unintended memory locations, potentially achieving code execution beyond the VIRTIO-Net component in multi-tenant cloud/virtualized environments. NVIDIA discovered the flaw internally and shipped patched releases across all supported branches; no public PoC or active exploitation has been reported.

CVE-2026-65094 is a CWE-123 write-what-where condition in NVIDIA's VIRTIO-Net implementation, the paravirtualized network device interface that BlueField-3 Data Processing Units (DPUs) and ConnectX networking adapters expose to guest virtual machines. According to NVIDIA's July 2026 security bulletin (referenced by multiple independent outlets as product-security-portal answer a_id/5815, titled "Security Bulletin: NVIDIA Networking BlueField, ConnectX - July 2026" per stack.watch's NVIDIA advisory index) and corroborating technical writeups, a virtual machine user holding only low privileges can send a specially crafted message to the VIRTIO-Net component that causes it to write attacker-controlled data to unintended memory locations. This write-what-where memory-corruption primitive can be escalated to arbitrary code execution within the VIRTIO-Net context.

The flaw carries a CVSS v3.1 base score of 9.0. Independent technical summaries consistently describe the attack vector as Adjacent (reachable by a VM sharing the host's virtual network fabric rather than the public internet), attack complexity Low, privileges required Low (a legitimate but unprivileged tenant VM account), no user interaction, and a scope change -- meaning successful exploitation can affect resources beyond the vulnerable VIRTIO-Net component itself, i.e. the host/DPU context, with full confidentiality, integrity, and availability impact. Reconstructing the CVSS 3.1 vector from these individually-sourced qualitative descriptors (AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) mathematically reproduces the reported 9.0 base score, corroborating the secondary reporting even though NVIDIA's own bulletin page could not be directly retrieved (HTTP 403 on two separate research attempts) and NVD had not yet indexed a CVSS record for this CVE as of the second corroboration pass (NVD CVE 2.0 API returned zero results, response timestamped 2026-08-02T03:07:10Z).

The reconstructed attack chain across all five independent technical writeups reviewed is consistent: (1) a malicious VM tenant crafts a specialized VIRTIO-Net message payload; (2) the message triggers a memory-manipulation defect in the VIRTIO-Net component's input handling; (3) arbitrary attacker-controlled data is written to unintended memory locations (the write-what-where primitive); (4) this can be leveraged for attacker-controlled code execution within the VIRTIO-Net component's process/execution scope; (5) the CVSS scope change (S:C) reflects that impact is not confined to VIRTIO-Net but can reach the broader DPU/host-adjacent context.

The practical risk scenario, repeated across every source reviewed, is a multi-tenant cloud or virtualization host where a customer-controlled VM is intentionally given only minimal privileges: the VIRTIO-Net bug lets that low-trust tenant potentially break out of its expected privilege boundary and corrupt memory in the DPU/host-adjacent VIRTIO-Net scope, which is the classic setup for a guest-to-host escape in DPU-offloaded virtualization architectures (BlueField DPUs are specifically marketed for offloading networking, storage, and security functions from the host CPU into an isolated ARM-based control plane -- a compromise of that plane is high-value because it sits outside the traditional hypervisor security boundary, potentially bypassing host-based EDR/monitoring entirely and giving visibility into every tenant's network traffic transiting the shared DPU).

Affected releases span all VIRTIO-Net branches NVIDIA currently supports: GA before 25.10.6, LTS25 before 25.10.2, LTS24 before 24.10.50, and LTS23 at 1.7.21 and earlier (fixed in 23.10.23). NVIDIA credits internal discovery, reports no active exploitation and no public proof-of-concept as of the July 29, 2026 disclosure, and directs customers to the DOCA downloads portal for the fixed packages. The CVE-2026-65094 identifier itself replaces an earlier provisional assignment (CVE-2025-33209) referenced in at least one technical summary, consistent with NVIDIA's practice of renumbering CVEs during coordinated-disclosure tracking refinement. Cross-referencing the CISA Known Exploited Vulnerabilities catalog (version 2026.07.29, 1,656 entries) confirms CVE-2026-65094 is not listed, and it is likewise absent from NVD's CVE 2.0 API response at research time -- both consistent with a freshly patched, non-exploited vendor disclosure rather than an active-exploitation event.

Notably, this disclosure is not isolated: NVD indexes a near-identical, directly related prior disclosure -- CVE-2025-23351 (and its sibling CVE-2025-23350) -- published July 1, 2026, exactly four weeks before CVE-2026-65094, affecting the same NVIDIA ConnectX/BlueField product family. CVE-2025-23351 shares the IDENTICAL reconstructed CVSS 3.1 vector (AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, base score 9.0) and describes the same root-cause pattern: "a local user with virtual function (VF) access may cause a write out of bounds by crafted input" in the ConnectX/BlueField command interface (CWE-787, Out-of-bounds Write, a close sibling of CWE-123), with NVIDIA's own advisory noting that on ConnectX-8 devices additional security mitigations "limit exploitation" and that a successful exploit "would require an attacker to invest significant resources to bypass those security mechanisms." Taken together, these two disclosures four weeks apart indicate a recurring memory-safety weakness pattern across NVIDIA's DPU/SmartNIC command and paravirtualized-device interfaces (command interface and VIRTIO-Net respectively) through mid-2026, both reachable by a low-privileged local/VM tenant and both carrying the maximum CVSS 9.0 score for this exploitation class -- a pattern worth tracking for defenders operating BlueField/ConnectX fleets rather than treating CVE-2026-65094 as an isolated one-off.

MITRE ATT&CK techniques used in TL-2026-1812

Collection

T1005 Data from Local System

Defense Evasion

T1014 Rootkit; T1211 Exploitation for Stealth

Credential Access

T1040 Network Sniffing

Discovery

T1040 Network Sniffing

stealth

T1055 Process Injection

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1611 Escape to Host

Initial Access

T1078 Valid Accounts

Execution

T1203 Exploitation for Client Execution

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1495 Firmware Corruption; T1499 Endpoint Denial of Service

Persistence

T1542 Pre-OS Boot

Reconnaissance

T1595 Active Scanning

privilege-escalation

T1611 Escape to Host

Affected products and versions in CVE-2026-65094

  • NVIDIA — BlueField-3 DPU / ConnectX VIRTIO-Net (GA)
    Vulnerable versions: all versions before 25.10.6
    Fixed in: 25.10.6
  • NVIDIA — BlueField-3 DPU / ConnectX VIRTIO-Net (LTS25)
    Vulnerable versions: before 25.10.2
    Fixed in: 25.10.2
  • NVIDIA — BlueField-3 DPU / ConnectX VIRTIO-Net (LTS24)
    Vulnerable versions: before 24.10.50
    Fixed in: 24.10.50
  • NVIDIA — BlueField-3 DPU / ConnectX VIRTIO-Net (LTS23)
    Vulnerable versions: 1.7.21 and earlier
    Fixed in: 23.10.23

Remediation for CVE-2026-65094

Patches

  • NVIDIA VIRTIO-Net GA 25.10.6
  • NVIDIA VIRTIO-Net LTS25 25.10.2
  • NVIDIA VIRTIO-Net LTS24 24.10.50
  • NVIDIA VIRTIO-Net LTS23 23.10.23

Immediate actions

  • Inventory all BlueField-3 DPU and ConnectX deployments and identify which VIRTIO-Net branch (GA/LTS25/LTS24/LTS23) they run.
  • Upgrade VIRTIO-Net GA deployments to 25.10.6 or later.
  • Upgrade VIRTIO-Net LTS25 deployments to 25.10.2 or later.
  • Upgrade VIRTIO-Net LTS24 deployments to 24.10.50 or later.
  • Upgrade VIRTIO-Net LTS23 deployments to 23.10.23 or later.

Workarounds

  • No vendor-published workaround short of patching was identified; NVIDIA's guidance is to apply the fixed package for the deployed branch via the DOCA downloads portal.

Longer-term hardening

  • Audit VM isolation and tenant-privilege controls on any multi-tenant host using DPU-offloaded networking.
  • Deploy monitoring for anomalous or malformed VIRTIO-Net/virtqueue traffic between guest VMs and the DPU control plane.
  • Apply defense-in-depth network segmentation between tenant VM networks and DPU/host management planes.
  • Establish a recurring patch-tracking process against NVIDIA's monthly BlueField/ConnectX security bulletins, including the sibling CVE-2025-23351/CVE-2025-23350 command-interface out-of-bounds-write disclosures which follow the same low-privileged local/VF-access exploitation pattern.
  • Restrict or closely audit virtual function (VF) access grants on ConnectX/BlueField devices given the recurring crafted-input memory-corruption pattern across both the VIRTIO-Net and command-interface components.

CVEs associated with CVE-2026-65094

CVE-2026-65094

Weaknesses (CWE) in CVE-2026-65094

CWE-123

Timeline of CVE-2026-65094

  • NVIDIA discloses the related CVE-2025-23351 / CVE-2025-23350 (ConnectX/BlueField command-interface out-of-bounds write, CWE-787, identical reconstructed CVSS 3.1 9.0 vector AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) exactly four weeks before CVE-2026-65094, establishing a recurring crafted-input memory-corruption pattern across NVIDIA's DPU/SmartNIC interfaces.
  • SecurityOnline.info and Cyberpress.org independently publish corroborating technical summaries, adding CVSS component detail (adjacent vector, scope change, full CIA impact) and confirming the CVE-2025-33209 to CVE-2026-65094 renumbering.
  • Cyber Security News publishes the first widely-cited third-party technical writeup of CVE-2026-65094, detailing the five-step attack chain (craft message, trigger memory manipulation, write arbitrary data, achieve code execution, scope change beyond VIRTIO-Net).
  • NVIDIA and independent outlets report no active exploitation and no public proof-of-concept for CVE-2026-65094 as of disclosure.
  • NVIDIA publishes patched VIRTIO-Net releases across all supported branches (GA 25.10.6, LTS25 25.10.2, LTS24 24.10.50, LTS23 23.10.23) via the DOCA downloads portal.
  • NVIDIA discloses CVE-2026-65094 in its July 2026 Networking BlueField and ConnectX security bulletin (a_id/5815), crediting internal discovery of the write-what-where VIRTIO-Net flaw.
  • GBHackers and TeamWin publish follow-on coverage reiterating affected versions and urging immediate patching in data center/HPC environments.
  • TL-Intel Harness HUNT phase ingests the disclosure and creates threat skeleton TL-2026-1812; RESEARCH phase corroborates via CISA KEV (absent) and NVD (not yet indexed).
  • RESEARCH phase re-confirms CVE-2026-65094 is still absent from the NVD CVE 2.0 API (zero results) and cross-references NVD's entry for the related CVE-2025-23351 (published 2026-07-01, identical CVSS 9.0 vector) to corroborate the pattern of low-privileged VF/VM-access memory-corruption disclosures across NVIDIA's ConnectX/BlueField product line.

Sources cited for CVE-2026-65094

Detection coverage for TL-2026-1812

As of 2026-08-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1812 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats