CVE-2026-65124

MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denia...

CVSS 3.15.9
EPSS0.5%
Percentile42th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, high complexity, high privileges required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-91: CWE-91
Related Attack Patterns (CAPEC)
CAPEC-83 XPath Injection
via CWE-91
CAPEC-250 XML Injection
via CWE-91

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A medium severity vulnerability (CVE-2026-65124) affects the target system. NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-65124?
A medium severity vulnerability (CVE-2026-65124) affects the target system. NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.
What is the CVSS score for CVE-2026-65124?
CVE-2026-65124 has CVSS 5.9 (Medium). Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H. EPSS: 0.5%.
Is CVE-2026-65124 actively exploited?
No confirmed active exploitation of CVE-2026-65124 as of 2026-09-25.
How do I remediate CVE-2026-65124?
Apply vendor patches for CVE-2026-65124. Monitor the vendor advisories.
Vulnerability Details
CVE IDCVE-2026-65124
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
Published2026-09-22
Last Modified2026-09-22
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.

Source: NIST NVD / MITRE CVE Database

Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 6 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →