NVIDIA NVIDIA

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any NVIDIA product.

RSS Feeds for NVIDIA security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in NVIDIA products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by NVIDIA Sorted by Most Security Vulnerabilities since 2018

NVIDIA Gpu Display Driver78 vulnerabilities

NVIDIA Triton Inference Server65 vulnerabilities

NVIDIA Virtual Gpu Manager46 vulnerabilities

NVIDIA Nemo45 vulnerabilities

NVIDIA Cuda Toolkit44 vulnerabilities

NVIDIA Geforce26 vulnerabilities

NVIDIA Tesla25 vulnerabilities

NVIDIA Jetson22 vulnerabilities

NVIDIA Geforce Experience18 vulnerabilities

NVIDIA Megatron Lm11 vulnerabilities

NVIDIA Gpu Driver7 vulnerabilities

NVIDIA Cumulus Linux5 vulnerabilities

NVIDIA Aistore3 vulnerabilities

NVIDIA Onyx3 vulnerabilities

NVIDIA Mlnx Os3 vulnerabilities

Nvidia Gpu Operator1 vulnerability

NVIDIA Bluefield1 vulnerability

NVIDIA Quadro1 vulnerability

NVIDIA Runai1 vulnerability

NVIDIA Skyway1 vulnerability

NVIDIA Studio1 vulnerability

NVIDIA Titan V Firmware1 vulnerability

NVIDIA Connectx1 vulnerability

NVIDIA Cv Cuda1 vulnerability

NVIDIA Igx1 vulnerability

NVIDIA Isaac Lab1 vulnerability

NVIDIA Jetson Linux1 vulnerability

Nvidia Container Toolkit1 vulnerability

NVIDIA Mellanox Os1 vulnerability

NVIDIA Metrox 21 vulnerability

NVIDIA Metrox 3 Xc1 vulnerability

NVIDIA Nsight Graphics1 vulnerability

NVIDIA Nvapp1 vulnerability

NVIDIA Nvdebug Tool1 vulnerability

Nvidia App1 vulnerability

Recent NVIDIA Security Advisories

Advisory Title Published
5875 Security Bulletin - Triton Inference Server - August 2026 September 8, 2026
5868 Security Bulletin: Megatron Bridge - September 2026 September 1, 2026
5872 Security Bulletin: NVIDIA NemoClaw and OpenShell - August 2026 August 25, 2026
5809 Security Bulletin: NVIDIA Unified Fabric Manager - August 2026 August 25, 2026
5867 Security Bulletin - NVIDIA DGX Spark - August 2026 August 25, 2026
5817 Security Bulletin: NVIDIA Cumulus Linux and NVOS - August 2026 August 18, 2026
5865 Security Bulletin: NVIDIA Triton Inference Server - August 2026 August 18, 2026
5860 Security Bulletin: NVIDIA Triton Inference Server - August 2026 August 4, 2026
5842 Security Bulletin: NVIDIA Dynamo - August 2026 August 4, 2026
5857 Security Bulletin: NVIDIA DCGM Exporter - July 2026 July 28, 2026

By the Year

In 2026 there have been 226 vulnerabilities in NVIDIA with an average score of 7.5 out of ten. Last year, in 2025 NVIDIA had 174 security vulnerabilities published. That is, 52 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.72.




Year Vulnerabilities Average Score
2026 226 7.47
2025 174 6.74
2024 34 6.81
2023 28 6.22
2022 43 6.70
2021 75 6.54
2020 35 6.78
2019 16 6.90
2018 7 5.50

It may take a day or so for new NVIDIA vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent NVIDIA Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-47625 Sep 08, 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
Triton Inference Server
CVE-2026-16497 Sep 08, 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-61769 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61769) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61777 Sep 01, 2026
Deserialization Vulnerability in NVIDIA Megatron Bridge Leads to RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61778 Sep 01, 2026
Deserialization Vulnerability in NVIDIA Megatron Bridge NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61779 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability (untrusted data) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61770 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61771 Sep 01, 2026
NVIDIA Megatron Bridge Untrusted Deserialization Leads to Code Exec NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61772 Sep 01, 2026
Deserialization in NVIDIA Megatron Bridge Enables RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61773 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61773) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61774 Sep 01, 2026
NVIDIA Megatron Bridge - Deserialization Vulnerability (CVE-2026-61774) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61775 Sep 01, 2026
Untrusted Deserialization in NVIDIA Megatron Bridge RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61776 Sep 01, 2026
Deserialization Vulnerability in NVIDIA Megatron Bridge Enabling RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61766 Sep 01, 2026
NVIDIA Megatron Bridge: Untrusted Deserialization RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61767 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization for Code Execution NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61768 Sep 01, 2026
NVIDIA Megatron Bridge deserialization vuln allows code exec NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61760 Sep 01, 2026
Deserialization Exploit in NVIDIA Megatron Bridge Allows Remote Code Execution. NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61761 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61761) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61762 Sep 01, 2026
Deserialization Vulnerability in NVIDIA Megatron Bridge Enables Code Exec NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61763 Sep 01, 2026
Deserialization Vulnerability in NVIDIA Megatron Bridge Enables RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61764 Sep 01, 2026
NVIDIA Megatron Bridge Deser Exploit: Code Exec Risk NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61765 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability Enabling RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61759 Sep 01, 2026
NVIDIA Megatron Bridge: Unsafe De-serialize Enables RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61750 Sep 01, 2026
NVIDIA Megatron Bridge Untrusted Deserialization Enables RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61751 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Exploit Enables RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61752 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61752) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61753 Sep 01, 2026
Deserialization Bypass in NVIDIA Megatron Bridge Enables RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61754 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61754) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61758 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61758) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61755 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61755) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61756 Sep 01, 2026
NVIDIA Megatron Bridge: Deserialization flaw allows RCE NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61757 Sep 01, 2026
NVIDIA Megatron Bridge Deserialization Vulnerability (CVE-2026-61757) NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-65105 Aug 25, 2026
NVIDIA NemoClaw: Inference Service Bypass (auth) Info Leak & DoS NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
Nemo
CVE-2026-65088 Aug 25, 2026
NVIDIA NemoClaw Info Disclosure via Sensitive Data Process Invocation NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
Nemo
CVE-2026-65087 Aug 25, 2026
NVIDIA NemoClaw: Credential Exposure Leading to Info Disclosure & Tampering NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.
Nemo
CVE-2026-65086 Aug 25, 2026
OS Command Injection in NVIDIA OpenShell Exec Handler NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CVE-2026-65085 Aug 25, 2026
NVIDIA OpenShell Linux Inference Proxy Improper Encoding Vulnerability NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
CVE-2026-65084 Aug 25, 2026
NVIDIA NemoClaw Improper Cert Validation in Deployment Process NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.
Nemo
CVE-2026-65083 Aug 25, 2026
NVIDIA OpenShell Sandbox API Privilege Escalation Vulnerability NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
CVE-2026-65082 Aug 25, 2026
Local code injection in NVIDIA NemoClaw Linux migration command NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65081 Aug 25, 2026
NVIDIA NemoClaw InstaExec: Untrusted Code Exec Priv Esc NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65089 Aug 25, 2026
NVIDIA NemoClaw Linux OS Command Injection via Status/Logs Plugin NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65090 Aug 25, 2026
NVIDIA NemoClaw NIM OS Command Injection Vulnerability NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65099 Aug 25, 2026
NVIDIA NemoClaw CLI OS Command Injection NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65098 Aug 25, 2026
NVIDIA NemoClaw Linux Remote-Access Helper Weak Auth Vulnerability NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Nemo
CVE-2026-65097 Aug 25, 2026
NVIDIA NemoClaw Linux Install Script Lacks Integrity, May Allow Code Exec NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Nemo
CVE-2026-65096 Aug 25, 2026
NVIDIA NemoClaw OS Cmd Injection via Telegram Bridge (CVE-2026-65096) NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Nemo
CVE-2026-65093 Aug 25, 2026
NVIDIA OpenShell Linux Sandbox Escape Vulnerability NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-65092 Aug 25, 2026
NVIDIA OpenShell Sandbox L7 REST Network Policy Path Traversal Bypass NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
CVE-2026-65091 Aug 25, 2026
NVIDIA OpenShell OS Command Injection via Malicious Gateway NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.