By vendor
Nvidia vulnerabilities
Known CVEs affecting Nvidia products, prioritized by severity, with SEC.co remediation and detection guidance.
17 published vulnerabilities
- CVE-2026-24155HIGH 7.8
NVIDIA's NeMo Framework contains a code injection vulnerability that allows an attacker with local access and limited user privileges to execute arbitrary code on affected systems. The vulnerability is rooted in unsafe handling of code execution paths, enabling attackers to escalate privileges, steal sensitive data, or modify system information. This is a significant risk for organizations running NeMo-based machine learning applications, particularly in research and production environments where model training or inference occurs.
- CVE-2026-24221HIGH 7.8
NVIDIA's NVTabular library contains a deserialization vulnerability that could allow an authenticated attacker to execute arbitrary code, modify data, or steal sensitive information. The vulnerability is rated HIGH severity and requires local system access and valid user credentials to exploit. While not currently listed as actively exploited, this flaw merits prompt attention given the potential for code execution on systems processing sensitive machine learning datasets.
- CVE-2026-24228HIGH 7.8
NVIDIA NeMo Framework for Linux has a vulnerability that allows an attacker with local access to execute arbitrary code by providing specially crafted data that the application deserializes without validation. This could give an attacker elevated privileges, the ability to modify data, or access to sensitive information. The vulnerability requires the attacker to already have local user-level access to the system.
- CVE-2026-24237HIGH 7.8
NVIDIA NVTabular is vulnerable to unsafe deserialization of untrusted data. An attacker with local access and basic user privileges could exploit this flaw to execute arbitrary code, modify data, or steal sensitive information from systems running the affected software.
- CVE-2026-24240HIGH 7.8
NVIDIA Megatron Bridge for Linux has a security flaw that allows attackers to execute arbitrary code on affected systems by tricking them into processing malicious data. An attacker without special permissions can exploit this vulnerability if a user interacts with a specially crafted file or input, potentially taking full control of the system, stealing sensitive data, or modifying files. The vulnerability affects the deserialization process—how the application reconstructs data from storage—and is rated as HIGH severity.
- CVE-2026-24242HIGH 7.8
NVIDIA's Megatron Bridge for Linux has a vulnerability that lets an attacker trick the server into making unintended network requests on its behalf. This type of flaw, known as server-side request forgery (SSRF), could allow an attacker to access sensitive information that the server can reach but the attacker normally could not. The vulnerability requires local access and user interaction to exploit, making it a meaningful but not trivial threat to systems running vulnerable versions.
- CVE-2026-24243HIGH 7.8
NVIDIA's Megatron Bridge for Linux has a flaw that allows attackers to execute malicious code on affected systems by tricking them into processing untrusted data. The vulnerability requires local access and user interaction, but successful exploitation could give an attacker full control over the system, access to sensitive information, and the ability to modify or delete data. This is a significant risk for organizations running NVIDIA's deep learning infrastructure components.
- CVE-2026-24244HIGH 7.8
NVIDIA Megatron Bridge for Linux is vulnerable to unsafe deserialization, where an attacker can trick the software into processing malicious data. If successful, an attacker could run arbitrary code on the affected system, steal sensitive information, modify data, or gain elevated privileges. The vulnerability requires local access and user interaction (such as opening a malicious file), but poses significant risk to systems where Megatron Bridge processes untrusted input.
- CVE-2026-24245HIGH 7.8
NVIDIA's Megatron Bridge for Linux contains a deserialization vulnerability that could allow an attacker to execute arbitrary code on an affected system. The vulnerability requires local access and user interaction—an attacker cannot exploit it remotely. If successfully exploited, the impact is severe: an attacker could run commands with the privileges of the affected user, tamper with data, steal sensitive information, or escalate privileges further. This is a local attack surface, meaning the threat actor must already have a presence on the target machine or trick a user into opening a malicious file.
- CVE-2026-24246HIGH 7.8
NVIDIA's Megatron Bridge for Linux has a flaw that allows attackers to execute arbitrary code on affected systems. The vulnerability stems from improper handling of dynamically managed code resources, meaning an attacker could manipulate how the system loads and runs code. A user must interact with a malicious element to trigger the attack, but no special privileges are required. Successful exploitation could lead to complete system compromise, including unauthorized code execution, privilege escalation, unauthorized data access, and data modification.
- CVE-2026-24247HIGH 7.8
NVIDIA's Megatron Bridge for Linux has a serious flaw that allows attackers to trick the software into processing malicious data. When an attacker sends specially crafted input, the application deserializes it without proper validation, potentially giving the attacker the ability to run code on the affected system, steal sensitive information, modify data, or gain elevated privileges. The vulnerability requires user interaction (such as opening a file or clicking a link) but no authentication.
- CVE-2026-24248HIGH 7.8
NVIDIA's Megatron Bridge for Linux has a flaw that lets an attacker manipulate how code is generated on a system. If exploited, this could allow unauthorized code execution, privilege escalation, data modification, or theft of sensitive information. The vulnerability requires local access and user interaction to trigger, but the potential damage spans multiple security domains.
- CVE-2026-24249HIGH 7.8
NVIDIA's Megatron Bridge for Linux has a flaw that allows an attacker with local access to inject malicious data into the application, leading to arbitrary code execution. Because the vulnerable code doesn't properly validate serialized data before processing it, a local user can exploit this to run commands with the same privileges as the application, steal sensitive information, or modify data on the system.
- CVE-2026-24250HIGH 7.8
NVIDIA Megatron Bridge for Linux has a vulnerability that fails to properly validate user inputs, potentially allowing an attacker with local access to execute code, gain elevated privileges, tamper with data, or steal sensitive information. The vulnerability requires an authenticated user on the system to exploit, but once triggered, the impact is severe.
- CVE-2026-24251HIGH 7.8
NVIDIA's Megatron Bridge for Linux has a vulnerability that allows an attacker with local access to execute arbitrary code and gain elevated privileges on affected systems. The flaw stems from improper handling of dynamic code resources, which could let an authenticated user manipulate how the system manages executable code in memory. This is a serious issue for any organization running machine learning workloads that rely on Megatron optimization frameworks.
- CVE-2026-24264HIGH 7.5
NVIDIA Triton Inference Server running on Linux has a vulnerability that allows remote attackers to crash the service by sending specially crafted highly compressed data. An attacker needs no credentials or user interaction to trigger this denial-of-service condition, making it a straightforward attack vector. The vulnerability does not enable data theft or system compromise, but availability impact can be significant for organizations relying on Triton for AI inference workloads.
- CVE-2026-24266MEDIUM 5.9
NVIDIA's Triton Inference Server for Linux contains a use-after-free vulnerability that allows attackers to disrupt service availability. The flaw exists in memory management logic, where freed memory is accessed again, potentially causing the application to crash. While the attack requires specific network conditions to exploit reliably, the impact is limited to denial of service rather than data theft or system compromise.