Junglewise Threat Intelligence

CVE-2026-65129: NVIDIA Infrastructure Controller for Linux improper certificate validation

CVE-2026-65129 · Severity: medium · CVSS 6.7 · Published 2026-09-22

Vendors: Nvidia.

Executive brief

NVIDIA Infrastructure Controller for Linux is a system management tool that handles authentication and secure communications for Linux servers. An attacker could bypass certificate validation checks to intercept, modify, or deny access to infrastructure management functions, potentially exposing sensitive system information or disrupting server operations.

Technical details

The vulnerability is an improper certificate validation flaw in NVIDIA Infrastructure Controller for Linux that allows attackers to bypass security checks. The attack vector is network-based and requires no authentication or user interaction. Successful exploitation could lead to man-in-the-middle attacks enabling information disclosure, data tampering, and denial of service.

Affected products

  • NVIDIA Infrastructure Controller for Linux

Timeline

  • 2026-09-22: disclosed

References

Related threats