NVIDIA
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any NVIDIA product.
RSS Feeds for NVIDIA security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in NVIDIA products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by NVIDIA Sorted by Most Security Vulnerabilities since 2018
Recent NVIDIA Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 5875 | Security Bulletin - Triton Inference Server - August 2026 | September 8, 2026 |
| 5868 | Security Bulletin: Megatron Bridge - September 2026 | September 1, 2026 |
| 5872 | Security Bulletin: NVIDIA NemoClaw and OpenShell - August 2026 | August 25, 2026 |
| 5809 | Security Bulletin: NVIDIA Unified Fabric Manager - August 2026 | August 25, 2026 |
| 5867 | Security Bulletin - NVIDIA DGX Spark - August 2026 | August 25, 2026 |
| 5817 | Security Bulletin: NVIDIA Cumulus Linux and NVOS - August 2026 | August 18, 2026 |
| 5865 | Security Bulletin: NVIDIA Triton Inference Server - August 2026 | August 18, 2026 |
| 5860 | Security Bulletin: NVIDIA Triton Inference Server - August 2026 | August 4, 2026 |
| 5842 | Security Bulletin: NVIDIA Dynamo - August 2026 | August 4, 2026 |
| 5857 | Security Bulletin: NVIDIA DCGM Exporter - July 2026 | July 28, 2026 |
By the Year
In 2026 there have been 226 vulnerabilities in NVIDIA with an average score of 7.5 out of ten. Last year, in 2025 NVIDIA had 174 security vulnerabilities published. That is, 52 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.72.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 226 | 7.47 |
| 2025 | 174 | 6.74 |
| 2024 | 34 | 6.81 |
| 2023 | 28 | 6.22 |
| 2022 | 43 | 6.70 |
| 2021 | 75 | 6.54 |
| 2020 | 35 | 6.78 |
| 2019 | 16 | 6.90 |
| 2018 | 7 | 5.50 |
It may take a day or so for new NVIDIA vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent NVIDIA Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-47625 | Sep 08, 2026 |
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorizationNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. |
|
| CVE-2026-16497 | Sep 08, 2026 |
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iterationNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-61769 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61769)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61777 | Sep 01, 2026 |
Deserialization Vulnerability in NVIDIA Megatron Bridge Leads to RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61778 | Sep 01, 2026 |
Deserialization Vulnerability in NVIDIA Megatron BridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61779 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability (untrusted data)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61770 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization VulnerabilityNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61771 | Sep 01, 2026 |
NVIDIA Megatron Bridge Untrusted Deserialization Leads to Code ExecNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61772 | Sep 01, 2026 |
Deserialization in NVIDIA Megatron Bridge Enables RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61773 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61773)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61774 | Sep 01, 2026 |
NVIDIA Megatron Bridge - Deserialization Vulnerability (CVE-2026-61774)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61775 | Sep 01, 2026 |
Untrusted Deserialization in NVIDIA Megatron Bridge RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61776 | Sep 01, 2026 |
Deserialization Vulnerability in NVIDIA Megatron Bridge Enabling RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61766 | Sep 01, 2026 |
NVIDIA Megatron Bridge: Untrusted Deserialization RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61767 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization for Code ExecutionNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61768 | Sep 01, 2026 |
NVIDIA Megatron Bridge deserialization vuln allows code execNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61760 | Sep 01, 2026 |
Deserialization Exploit in NVIDIA Megatron Bridge Allows Remote Code Execution.NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61761 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61761)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61762 | Sep 01, 2026 |
Deserialization Vulnerability in NVIDIA Megatron Bridge Enables Code ExecNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61763 | Sep 01, 2026 |
Deserialization Vulnerability in NVIDIA Megatron Bridge Enables RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61764 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deser Exploit: Code Exec RiskNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61765 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability Enabling RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61759 | Sep 01, 2026 |
NVIDIA Megatron Bridge: Unsafe De-serialize Enables RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61750 | Sep 01, 2026 |
NVIDIA Megatron Bridge Untrusted Deserialization Enables RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61751 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Exploit Enables RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61752 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61752)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61753 | Sep 01, 2026 |
Deserialization Bypass in NVIDIA Megatron Bridge Enables RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61754 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61754)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61758 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61758)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61755 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61755)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61756 | Sep 01, 2026 |
NVIDIA Megatron Bridge: Deserialization flaw allows RCENVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-61757 | Sep 01, 2026 |
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61757)NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-65105 | Aug 25, 2026 |
NVIDIA NemoClaw: Inference Service Bypass (auth) Info Leak & DoSNVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service. |
|
| CVE-2026-65088 | Aug 25, 2026 |
NVIDIA NemoClaw Info Disclosure via Sensitive Data Process InvocationNVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-65087 | Aug 25, 2026 |
NVIDIA NemoClaw: Credential Exposure Leading to Info Disclosure & TamperingNVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering. |
|
| CVE-2026-65086 | Aug 25, 2026 |
OS Command Injection in NVIDIA OpenShell Exec HandlerNVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. |
|
| CVE-2026-65085 | Aug 25, 2026 |
NVIDIA OpenShell Linux Inference Proxy Improper Encoding VulnerabilityNVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering. |
|
| CVE-2026-65084 | Aug 25, 2026 |
NVIDIA NemoClaw Improper Cert Validation in Deployment ProcessNVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges. |
|
| CVE-2026-65083 | Aug 25, 2026 |
NVIDIA OpenShell Sandbox API Privilege Escalation VulnerabilityNVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service. |
|
| CVE-2026-65082 | Aug 25, 2026 |
Local code injection in NVIDIA NemoClaw Linux migration commandNVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65081 | Aug 25, 2026 |
NVIDIA NemoClaw InstaExec: Untrusted Code Exec Priv EscNVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65089 | Aug 25, 2026 |
NVIDIA NemoClaw Linux OS Command Injection via Status/Logs PluginNVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65090 | Aug 25, 2026 |
NVIDIA NemoClaw NIM OS Command Injection VulnerabilityNVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65099 | Aug 25, 2026 |
NVIDIA NemoClaw CLI OS Command InjectionNVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. |
|
| CVE-2026-65098 | Aug 25, 2026 |
NVIDIA NemoClaw Linux Remote-Access Helper Weak Auth VulnerabilityNVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. |
|
| CVE-2026-65097 | Aug 25, 2026 |
NVIDIA NemoClaw Linux Install Script Lacks Integrity, May Allow Code ExecNVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-65096 | Aug 25, 2026 |
NVIDIA NemoClaw OS Cmd Injection via Telegram Bridge (CVE-2026-65096)NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-65093 | Aug 25, 2026 |
NVIDIA OpenShell Linux Sandbox Escape VulnerabilityNVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-65092 | Aug 25, 2026 |
NVIDIA OpenShell Sandbox L7 REST Network Policy Path Traversal BypassNVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. |
|
| CVE-2026-65091 | Aug 25, 2026 |
NVIDIA OpenShell OS Command Injection via Malicious GatewayNVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |