Security NEXTJuly 29, 2026🇯🇵Translated from Japanese

NVIDIA Patches Critical VIRTIO-Net Flaw in BlueField 3 Allowing VM Code Execution

NVIDIA has issued a security update to address a critical vulnerability in the VIRTIO-Net component of its BlueField 3 DPU platform.

The flaw, identified as CVE-2026-65094, was disclosed in a security advisory published on July 28, 2026. It stems from improper handling of memory write operations and was discovered internally by the company. The original CVE identifier CVE-2025-33209 was withdrawn and replaced.

According to the advisory, a virtual machine user can exploit the vulnerability by sending specially crafted messages. This allows arbitrary values to be written to arbitrary memory locations, enabling code execution within the VIRTIO-Net execution context.

The vulnerability received a CVSS v3.1 base score of 9.0 and is rated Critical, the highest severity level.

NVIDIA recommends updating to the following fixed versions or later: VIRTIO-Net 25.10.6, 25.10.2, 24.10.50, and 23.10.23.

Related articles

Security NEXTVulnerabilities & Exploits

CISA Adds Ray AI Framework Flaw CVE-2025-62593 to KEV Catalog After Confirmed Exploitation

US authorities have issued a warning that a critical vulnerability in the Ray framework for scaling AI and Python applications is being actively exploited in real-world attacks. The flaw, tracked as CVE-2025-62593, allows remote code execution through browsers such as Firefox and Safari, potentially enabling attackers to run malicious code simply by displaying an ad on a compromised page. CISA added the issue to its Known Exploited Vulnerabilities catalog on August 17, 2026, and directed federal agencies to apply mitigations by August 20. Originally disclosed in November 2025 and fixed in Ray version 2.52.0, the vulnerability carries a CVSS v4.0 base score of 9.4 and is rated Critical. Developers using Ray in environments that also run Firefox or Safari face additional risk from DNS rebinding attacks that can lead to code injection. Organizations relying on Ray are urged to verify patch status and monitor for signs of compromise.

Security NEXTVulnerabilities & Exploits

GitLab Issues Critical Security Updates Fixing Unauthenticated Project Modification Flaws

GitLab has released security updates for its Community Edition and Enterprise Edition platforms to address two vulnerabilities, including one rated critical. The flaws were reported through the company's bug bounty program and affect multiple supported versions. CVE-2026-19478 is a code injection issue that allows remote attackers to tamper with or delete public projects and user data via GraphQL directives without authentication under certain conditions. CVE-2026-19650 is a CSRF vulnerability stemming from insufficient validation in GraphQL multiplexed query handling, enabling mutation execution through GET requests. Both CVEs received high CVSS scores, prompting GitLab to urge immediate upgrades to versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

AntiMalwareVulnerabilities & Exploits

VoLTE Video Call Vulnerability Grants Kernel Access on Unisoc Android Chips

Researchers from SSD Secure Disclosure have disclosed a two-stage attack chain that achieves remote kernel access on Android devices powered by Unisoc chipsets. The exploit begins with a remote code execution flaw in the modem firmware that is triggered by a specially crafted VoLTE video call. Once code executes on the modem, a second privilege-escalation issue abuses shared physical memory between the modem and application processor to reach Android kernel memory. The attack requires an attacker-controlled 4G network and VoLTE infrastructure, and the victim must answer the incoming video call. Vulnerable chip families include T606, T612 and T7250, found in devices such as the Motorola E13, Realme C33 and Xiaomi Redmi A5. No patch or CVE identifier has been issued by Unisoc, and the August Android security bulletin does not address the issue.

安全客Vulnerabilities & Exploits

SAP Commerce Cloud CVE-2026-58231 Critical Flaw Exploited in the Wild Just Three Days After Patch

SAP Commerce Cloud has been hit by a maximum-severity vulnerability tracked as CVE-2026-58231 that carries a CVSS score of 10.0. The flaw resides in the Data Hub Adapter component and allows unauthenticated remote code execution via a single crafted HTTP request. SAP released the official patch on 11 August, yet honeypots recorded the first exploitation attempts only three days later on 14 August. More than 4,200 internet-facing SAP Commerce Cloud instances have been identified worldwide, primarily in Europe and North America. Researchers note that AI-assisted patch analysis enabled attackers to weaponize the fix at unprecedented speed. Organizations are urged to apply the updates to versions 2211.55 or 2211-jdk21.17 immediately and restrict access to the affected endpoints in the meantime.