NVIDIA Infrastructure Controller Hit by 14 Security Flaws Enabling Privilege Escalation and Code Execution
Brief
NVIDIA has released version 2.0 of its Infrastructure Controller to remediate 14 security vulnerabilities in the Linux-based infrastructure-management software, including a critical hard-coded credentials flaw that could enable remote compromise.
The vulnerabilities affect versions 0 through 1.9, and NVIDIA is urging users to upgrade or clone the latest release from the project’s GitHub repository.
NVIDIA’s security bulletin, issued on September 22, 2026, rates the flaws from medium to critical severity under CVSS v3.1.
NVIDIA Infrastructure Controller Hit by 14 Security Flaws
Collectively, the weaknesses could expose affected deployments to code execution, privilege escalation, data tampering, denial-of-service conditions , and information disclosure. The highest-rated issue, CVE-2026-65113, carries a CVSS score of 9. 8.
