NVIDIA has 47 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 32 in the last 90 days against 7 in the 90 before. The busiest recent month was September 2026 with 21. The median CVSS is 7.8 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-502 (9) and CWE-787 (4). Most affected products: Infrastructure Controller (14), dgx_spark_uefi (5), bionemo_framework (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 32 prev 7
Products
- Infrastructure Controller 14
- dgx_spark_uefi 5
- bionemo_framework 4
- dynamo 4
- data_loading_library 3
- jetson_linux 3
Worst active — by depth score
CVE-2026-65113Critical· 9.8NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials54CVE-2026-24254Critical· 9.8NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write54CVE-2026-65179High· 8.8NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation49CVE-2026-65128High· 8.8NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection49CVE-2026-24217High· 8.8NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file49
NVIDIA vulnerabilities
CVEs affecting NVIDIA, newest first. Open any entry for full detail, references, and exploit status.
47 CVEsRSS
CVE-2026-24252High· 7.8NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
CVE-2026-24220Medium· 6.4NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization
NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to …
CVE-2026-24181High· 7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation
NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information d…
CVE-2026-24180High· 7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow
NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information d…
CVE-2026-24218High· 8.1NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems
NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all sim…
CVE-2026-24217High· 8.8NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclos…
CVE-2026-24216High· 7.8NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data
NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data …
CVE-2026-24188High· 8.2NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write
NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.
CVE-2026-24156High· 7.3NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data
NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.
CVE-2026-24165High· 7.8NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
CVE-2026-24164High· 8.8NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
CVE-2026-24154High· 7.6NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments
NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A successful exploit of this vulnerability might lead to code execution, escalation of pri…
CVE-2026-24153Medium· 5.2NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-24148High· 8.3NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might…
CVE-2025-33240High· 7.8NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection
NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informat…
CVE-2025-33239High· 7.8NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection
NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informatio…
CVE-2025-23339Low· 3.3PoCNVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerabilit…