NVIDIA NVIDIA

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any NVIDIA product.

RSS Feeds for NVIDIA security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in NVIDIA products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by NVIDIA Sorted by Most Security Vulnerabilities since 2018

NVIDIA Gpu Display Driver78 vulnerabilities

NVIDIA Triton Inference Server63 vulnerabilities

NVIDIA Virtual Gpu Manager46 vulnerabilities

NVIDIA Nemo45 vulnerabilities

NVIDIA Cuda Toolkit44 vulnerabilities

NVIDIA Geforce26 vulnerabilities

NVIDIA Tesla25 vulnerabilities

NVIDIA Jetson22 vulnerabilities

NVIDIA Geforce Experience18 vulnerabilities

NVIDIA Megatron Lm11 vulnerabilities

NVIDIA Gpu Driver7 vulnerabilities

NVIDIA Cumulus Linux5 vulnerabilities

NVIDIA Aistore3 vulnerabilities

NVIDIA Onyx3 vulnerabilities

NVIDIA Mlnx Os3 vulnerabilities

Nvidia Gpu Operator1 vulnerability

NVIDIA Bluefield1 vulnerability

NVIDIA Quadro1 vulnerability

NVIDIA Runai1 vulnerability

NVIDIA Skyway1 vulnerability

NVIDIA Studio1 vulnerability

NVIDIA Titan V Firmware1 vulnerability

NVIDIA Connectx1 vulnerability

NVIDIA Cv Cuda1 vulnerability

NVIDIA Igx1 vulnerability

NVIDIA Isaac Lab1 vulnerability

NVIDIA Jetson Linux1 vulnerability

Nvidia Container Toolkit1 vulnerability

NVIDIA Mellanox Os1 vulnerability

NVIDIA Metrox 21 vulnerability

NVIDIA Metrox 3 Xc1 vulnerability

NVIDIA Nsight Graphics1 vulnerability

NVIDIA Nvapp1 vulnerability

NVIDIA Nvdebug Tool1 vulnerability

Nvidia App1 vulnerability

Recent NVIDIA Security Advisories

Advisory Title Published
5872 Security Bulletin: NVIDIA NemoClaw and OpenShell - August 2026 August 25, 2026
5809 Security Bulletin: NVIDIA Unified Fabric Manager - August 2026 August 25, 2026
5867 Security Bulletin - NVIDIA DGX Spark - August 2026 August 25, 2026
5817 Security Bulletin: NVIDIA Cumulus Linux and NVOS - August 2026 August 18, 2026
5865 Security Bulletin: NVIDIA Triton Inference Server - August 2026 August 18, 2026
5860 Security Bulletin: NVIDIA Triton Inference Server - August 2026 August 4, 2026
5842 Security Bulletin: NVIDIA Dynamo - August 2026 August 4, 2026
5857 Security Bulletin: NVIDIA DCGM Exporter - July 2026 July 28, 2026
5815 Security Bulletin: NVIDIA Networking Bluefield, ConnectX - July 2026 July 28, 2026
5869 Security Bulletin - NVIDIA - Transformers4Rec - July 2026 July 21, 2026

By the Year

In 2026 there have been 194 vulnerabilities in NVIDIA with an average score of 7.4 out of ten. Last year, in 2025 NVIDIA had 174 security vulnerabilities published. That is, 20 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.67.




Year Vulnerabilities Average Score
2026 194 7.41
2025 174 6.74
2024 34 6.81
2023 28 6.22
2022 43 6.70
2021 75 6.54
2020 35 6.78
2019 16 6.90
2018 7 5.50

It may take a day or so for new NVIDIA vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent NVIDIA Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-65105 Aug 25, 2026
NVIDIA NemoClaw: Inference Service Bypass (auth) Info Leak & DoS NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
Nemo
CVE-2026-65088 Aug 25, 2026
NVIDIA NemoClaw Info Disclosure via Sensitive Data Process Invocation NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
Nemo
CVE-2026-65087 Aug 25, 2026
NVIDIA NemoClaw: Credential Exposure Leading to Info Disclosure & Tampering NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.
Nemo
CVE-2026-65086 Aug 25, 2026
OS Command Injection in NVIDIA OpenShell Exec Handler NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CVE-2026-65085 Aug 25, 2026
NVIDIA OpenShell Linux Inference Proxy Improper Encoding Vulnerability NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
CVE-2026-65084 Aug 25, 2026
NVIDIA NemoClaw Improper Cert Validation in Deployment Process NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.
Nemo
CVE-2026-65083 Aug 25, 2026
NVIDIA OpenShell Sandbox API Privilege Escalation Vulnerability NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
CVE-2026-65082 Aug 25, 2026
Local code injection in NVIDIA NemoClaw Linux migration command NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65081 Aug 25, 2026
NVIDIA NemoClaw InstaExec: Untrusted Code Exec Priv Esc NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65089 Aug 25, 2026
NVIDIA NemoClaw Linux OS Command Injection via Status/Logs Plugin NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65090 Aug 25, 2026
NVIDIA NemoClaw NIM OS Command Injection Vulnerability NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65099 Aug 25, 2026
NVIDIA NemoClaw CLI OS Command Injection NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Nemo
CVE-2026-65098 Aug 25, 2026
NVIDIA NemoClaw Linux Remote-Access Helper Weak Auth Vulnerability NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Nemo
CVE-2026-65097 Aug 25, 2026
NVIDIA NemoClaw Linux Install Script Lacks Integrity, May Allow Code Exec NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Nemo
CVE-2026-65096 Aug 25, 2026
NVIDIA NemoClaw OS Cmd Injection via Telegram Bridge (CVE-2026-65096) NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Nemo
CVE-2026-65093 Aug 25, 2026
NVIDIA OpenShell Linux Sandbox Escape Vulnerability NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-65092 Aug 25, 2026
NVIDIA OpenShell Sandbox L7 REST Network Policy Path Traversal Bypass NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
CVE-2026-65091 Aug 25, 2026
NVIDIA OpenShell OS Command Injection via Malicious Gateway NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-24166 Aug 25, 2026
NVIDIA UFM Enterprise Hard-Coded Key in Session Mgmt Exposes Privileges NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges.
CVE-2026-24168 Aug 25, 2026
NVIDIA UFM Enterprise IBDiagnet API Command Injection (CVE-2026-24168) NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API requests. A successful exploit of this vulnerability may lead to code execution, escalation of privileges and information disclosure.
CVE-2026-24167 Aug 25, 2026
NVIDIA UFM Enterprise API command injection (CVE-2026-24167) NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure.
CVE-2026-24169 Aug 25, 2026
Low-Priv Auth Code Injection in NVIDIA UFM Enterprise Plugin API NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure.
CVE-2026-24170 Aug 25, 2026
NVIDIA UFM Ent Auth Bypass: Crafted HTTP May Yield Code Exec NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.
CVE-2026-47624 Aug 25, 2026
NVIDIA DGX Spark UEFI Password Bypass via Privileged Local Exploit NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.
CVE-2026-24225 Aug 25, 2026
Out-of-Bounds Read in NVIDIA DGX Spark MM Firmware Disclosure NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-24263 Aug 25, 2026
Null Ptr Deref in NVIDIA DGX Spark Firmware Enables Priv Escalation NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
CVE-2026-47626 Aug 25, 2026
NVIDIA DGX Spark Firmware OOB Write Privilege Escalation NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
CVE-2026-24262 Aug 25, 2026
NVIDIA DGX Spark Firmware OOB Write Privileged Escalation NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
CVE-2026-47630 Aug 18, 2026
Absolute Path Traversal in NVIDIA Triton Inference Server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.
Triton Inference Server
CVE-2026-47629 Aug 18, 2026
NVIDIA Triton Inference Server Input Validation DoS Vulnerability NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.
Triton Inference Server
CVE-2026-47628 Aug 18, 2026
NVIDIA Triton Inference Server DOS via Unlimited Resource Allocation NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.
Triton Inference Server
CVE-2026-47627 Aug 18, 2026
NVIDIA Triton Inference Server Path Traversal NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.
Triton Inference Server
CVE-2026-47606 Aug 18, 2026
NVIDIA Triton Inference Server: Path Traversal Causing Code Execution NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.
Triton Inference Server
CVE-2026-24185 Aug 18, 2026
NVIDIA NVOS SSH Auth Path Bypass in PKA-Only Mode NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.
CVE-2026-24184 Aug 18, 2026
LLDP Daemon Buffer Overflow in NVIDIA Cumulus Linux NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution.
Cumulus Linux
CVE-2026-24183 Aug 18, 2026
Privilege Escalation via Improper User Mgmt in NVIDIA Cumulus Linux NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges.
Cumulus Linux
CVE-2026-47623 Aug 04, 2026
Deserialization-RX Vulnerability in NVIDIA Dynamo Linux NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-47622 Aug 04, 2026
NVIDIA Dynamo for Linux Sensitive Data Exposure via Error Messages NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47621 Aug 04, 2026
NVIDIA Dynamo Linux Race Condition in LoRA Manager Singleton NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-47620 Aug 04, 2026
NVIDIA Dynamo LoRA Manager Singleton Race Condition (Linux) NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.
CVE-2026-47619 Aug 04, 2026
NVIDIA Dynamo_Linux Examples/Recipes RCE & DoS Vulnerability NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CVE-2026-47618 Aug 04, 2026
SSRF in NVIDIA Dynamos Rust multimodal media fetcher NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47617 Aug 04, 2026
NVIDIA Dynamo SSRSF via DNS Rebinding NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47616 Aug 04, 2026
SSRF in NVIDIA Dynamo for Linux media fetch leads to info disclosure NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47615 Aug 04, 2026
NVIDIA Dynamo SSFR via crafted URL in multimodal request NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47614 Aug 04, 2026
NVIDIA Dynamo SSRF Vulnerability (CVE-2026-47614) NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47613 Aug 04, 2026
NVIDIA Dynamo Improper Pathname Restriction Leading to Info Disclosure NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47612 Aug 04, 2026
NVIDIA Dynamo Image Loader: Improper Path Restriction (CVE-2026-47612) NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-24255 Aug 04, 2026
NVIDIA Dynamo Cache Hash Collision Enables Data Tampering NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.
CVE-2026-24254 Aug 04, 2026
NVIDIA Dynamo OOB Write in multimodal serving topology (priv esc, DoS) NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.