NVIDIA
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any NVIDIA product.
RSS Feeds for NVIDIA security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in NVIDIA products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by NVIDIA Sorted by Most Security Vulnerabilities since 2018
Recent NVIDIA Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 5872 | Security Bulletin: NVIDIA NemoClaw and OpenShell - August 2026 | August 25, 2026 |
| 5809 | Security Bulletin: NVIDIA Unified Fabric Manager - August 2026 | August 25, 2026 |
| 5867 | Security Bulletin - NVIDIA DGX Spark - August 2026 | August 25, 2026 |
| 5817 | Security Bulletin: NVIDIA Cumulus Linux and NVOS - August 2026 | August 18, 2026 |
| 5865 | Security Bulletin: NVIDIA Triton Inference Server - August 2026 | August 18, 2026 |
| 5860 | Security Bulletin: NVIDIA Triton Inference Server - August 2026 | August 4, 2026 |
| 5842 | Security Bulletin: NVIDIA Dynamo - August 2026 | August 4, 2026 |
| 5857 | Security Bulletin: NVIDIA DCGM Exporter - July 2026 | July 28, 2026 |
| 5815 | Security Bulletin: NVIDIA Networking Bluefield, ConnectX - July 2026 | July 28, 2026 |
| 5869 | Security Bulletin - NVIDIA - Transformers4Rec - July 2026 | July 21, 2026 |
By the Year
In 2026 there have been 194 vulnerabilities in NVIDIA with an average score of 7.4 out of ten. Last year, in 2025 NVIDIA had 174 security vulnerabilities published. That is, 20 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.67.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 194 | 7.41 |
| 2025 | 174 | 6.74 |
| 2024 | 34 | 6.81 |
| 2023 | 28 | 6.22 |
| 2022 | 43 | 6.70 |
| 2021 | 75 | 6.54 |
| 2020 | 35 | 6.78 |
| 2019 | 16 | 6.90 |
| 2018 | 7 | 5.50 |
It may take a day or so for new NVIDIA vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent NVIDIA Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-65105 | Aug 25, 2026 |
NVIDIA NemoClaw: Inference Service Bypass (auth) Info Leak & DoSNVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service. |
|
| CVE-2026-65088 | Aug 25, 2026 |
NVIDIA NemoClaw Info Disclosure via Sensitive Data Process InvocationNVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-65087 | Aug 25, 2026 |
NVIDIA NemoClaw: Credential Exposure Leading to Info Disclosure & TamperingNVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering. |
|
| CVE-2026-65086 | Aug 25, 2026 |
OS Command Injection in NVIDIA OpenShell Exec HandlerNVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. |
|
| CVE-2026-65085 | Aug 25, 2026 |
NVIDIA OpenShell Linux Inference Proxy Improper Encoding VulnerabilityNVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering. |
|
| CVE-2026-65084 | Aug 25, 2026 |
NVIDIA NemoClaw Improper Cert Validation in Deployment ProcessNVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges. |
|
| CVE-2026-65083 | Aug 25, 2026 |
NVIDIA OpenShell Sandbox API Privilege Escalation VulnerabilityNVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service. |
|
| CVE-2026-65082 | Aug 25, 2026 |
Local code injection in NVIDIA NemoClaw Linux migration commandNVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65081 | Aug 25, 2026 |
NVIDIA NemoClaw InstaExec: Untrusted Code Exec Priv EscNVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65089 | Aug 25, 2026 |
NVIDIA NemoClaw Linux OS Command Injection via Status/Logs PluginNVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65090 | Aug 25, 2026 |
NVIDIA NemoClaw NIM OS Command Injection VulnerabilityNVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65099 | Aug 25, 2026 |
NVIDIA NemoClaw CLI OS Command InjectionNVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65098 | Aug 25, 2026 |
NVIDIA NemoClaw Linux Remote-Access Helper Weak Auth VulnerabilityNVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. |
|
| CVE-2026-65097 | Aug 25, 2026 |
NVIDIA NemoClaw Linux Install Script Lacks Integrity, May Allow Code ExecNVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-65096 | Aug 25, 2026 |
NVIDIA NemoClaw OS Cmd Injection via Telegram Bridge (CVE-2026-65096)NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-65093 | Aug 25, 2026 |
NVIDIA OpenShell Linux Sandbox Escape VulnerabilityNVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-65092 | Aug 25, 2026 |
NVIDIA OpenShell Sandbox L7 REST Network Policy Path Traversal BypassNVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. |
|
| CVE-2026-65091 | Aug 25, 2026 |
NVIDIA OpenShell OS Command Injection via Malicious GatewayNVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-24166 | Aug 25, 2026 |
NVIDIA UFM Enterprise Hard-Coded Key in Session Mgmt Exposes PrivilegesNVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges. |
|
| CVE-2026-24168 | Aug 25, 2026 |
NVIDIA UFM Enterprise IBDiagnet API Command Injection (CVE-2026-24168)NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API requests. A successful exploit of this vulnerability may lead to code execution, escalation of privileges and information disclosure. |
|
| CVE-2026-24167 | Aug 25, 2026 |
NVIDIA UFM Enterprise API command injection (CVE-2026-24167)NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure. |
|
| CVE-2026-24169 | Aug 25, 2026 |
Low-Priv Auth Code Injection in NVIDIA UFM Enterprise Plugin APINVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure. |
|
| CVE-2026-24170 | Aug 25, 2026 |
NVIDIA UFM Ent Auth Bypass: Crafted HTTP May Yield Code ExecNVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and escalation of privileges. |
|
| CVE-2026-47624 | Aug 25, 2026 |
NVIDIA DGX Spark UEFI Password Bypass via Privileged Local ExploitNVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi. |
|
| CVE-2026-24225 | Aug 25, 2026 |
Out-of-Bounds Read in NVIDIA DGX Spark MM Firmware DisclosureNVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-24263 | Aug 25, 2026 |
Null Ptr Deref in NVIDIA DGX Spark Firmware Enables Priv EscalationNVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. |
|
| CVE-2026-47626 | Aug 25, 2026 |
NVIDIA DGX Spark Firmware OOB Write Privilege EscalationNVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. |
|
| CVE-2026-24262 | Aug 25, 2026 |
NVIDIA DGX Spark Firmware OOB Write Privileged EscalationNVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. |
|
| CVE-2026-47630 | Aug 18, 2026 |
Absolute Path Traversal in NVIDIA Triton Inference ServerNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution. |
|
| CVE-2026-47629 | Aug 18, 2026 |
NVIDIA Triton Inference Server Input Validation DoS VulnerabilityNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service. |
|
| CVE-2026-47628 | Aug 18, 2026 |
NVIDIA Triton Inference Server DOS via Unlimited Resource AllocationNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service. |
|
| CVE-2026-47627 | Aug 18, 2026 |
NVIDIA Triton Inference Server Path TraversalNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service. |
|
| CVE-2026-47606 | Aug 18, 2026 |
NVIDIA Triton Inference Server: Path Traversal Causing Code ExecutionNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure. |
|
| CVE-2026-24185 | Aug 18, 2026 |
NVIDIA NVOS SSH Auth Path Bypass in PKA-Only ModeNVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges. |
|
| CVE-2026-24184 | Aug 18, 2026 |
LLDP Daemon Buffer Overflow in NVIDIA Cumulus LinuxNVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24183 | Aug 18, 2026 |
Privilege Escalation via Improper User Mgmt in NVIDIA Cumulus LinuxNVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges. |
|
| CVE-2026-47623 | Aug 04, 2026 |
Deserialization-RX Vulnerability in NVIDIA Dynamo LinuxNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. |
|
| CVE-2026-47622 | Aug 04, 2026 |
NVIDIA Dynamo for Linux Sensitive Data Exposure via Error MessagesNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47621 | Aug 04, 2026 |
NVIDIA Dynamo Linux Race Condition in LoRA Manager SingletonNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering. |
|
| CVE-2026-47620 | Aug 04, 2026 |
NVIDIA Dynamo LoRA Manager Singleton Race Condition (Linux)NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service. |
|
| CVE-2026-47619 | Aug 04, 2026 |
NVIDIA Dynamo_Linux Examples/Recipes RCE & DoS VulnerabilityNVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-47618 | Aug 04, 2026 |
SSRF in NVIDIA Dynamos Rust multimodal media fetcherNVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47617 | Aug 04, 2026 |
NVIDIA Dynamo SSRSF via DNS RebindingNVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47616 | Aug 04, 2026 |
SSRF in NVIDIA Dynamo for Linux media fetch leads to info disclosureNVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47615 | Aug 04, 2026 |
NVIDIA Dynamo SSFR via crafted URL in multimodal requestNVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47614 | Aug 04, 2026 |
NVIDIA Dynamo SSRF Vulnerability (CVE-2026-47614)NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47613 | Aug 04, 2026 |
NVIDIA Dynamo Improper Pathname Restriction Leading to Info DisclosureNVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47612 | Aug 04, 2026 |
NVIDIA Dynamo Image Loader: Improper Path Restriction (CVE-2026-47612)NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-24255 | Aug 04, 2026 |
NVIDIA Dynamo Cache Hash Collision Enables Data TamperingNVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering. |
|
| CVE-2026-24254 | Aug 04, 2026 |
NVIDIA Dynamo OOB Write in multimodal serving topology (priv esc, DoS)NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. |