Výsledky hledání

výrobce: NVIDIA× v celém archivu zrušit filtry

15 karet z 15 položek CZ · EN/orig

1

NVIDIA security advisory (AV26-900)

Serial Number: AV26-900Date: September 9, 2026 As of September 8, 2026, NVIDIA is affected by vulnerabilities in the following product: Triton Inference Server Versions 0.0 to 26.03 Versions 0.0 to 26.06 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Bulletin: Triton Inference Server - September 2026 NVIDIA Product Security

NVIDIA CA

tg: zranitelnost tp: AI

· Cyber Centre Kanada · NVIDIA security advisory (AV26-900)

3

NVIDIA security advisory (AV26-849)

Serial Number: AV26-849Date: August 26, 2026 As of August 25, 2026, NVIDIA is affected by vulnerabilities in the following product: NVIDIA NemoClaw and OpenShell Multiple versions NVIDIA Unified Fabric Manager Multiple versions and models NVIDIA DGX Spark Versions prior to 1.110.13 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Bulletin: NVIDIA NemoClaw and OpenShell - August 2026 Security…

NVIDIA CA

· Cyber Centre Kanada · NVIDIA security advisory (AV26-849)

Risolte vulnerabilità in prodotti NVIDIA

Aggiornamenti di sicurezza NVIDIA risolvono 28 vulnerabilità, di cui 2 con gravità "critica" e 17 con gravità "alta", che interessano i prodotti NemoClaw, OpenShell, Unified Fabric Manager (UFM) Enterprise e DGX Spark. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eseguire codice arbitrario, elevare i propri privilegi, alterare i dati, accedere a informazioni sensibili e compromettere la disponibilità dei sistemi interessati.

NVIDIA IT

· CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti NVIDIA

4

ZDI-26-591: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24272.

EPSS 0.00 CVSS 7.8 CVE-2026-24272 NVIDIA US

· Zero Day Initiative · ZDI-26-591: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI-26-592: NVIDIA TensorRT ONNX File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24238.

EPSS 0.00 CVSS 7.8 CVE-2026-24238 NVIDIA US

· Zero Day Initiative · ZDI-26-592: NVIDIA TensorRT ONNX File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability

ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24268.

EPSS 0.00 CVSS 7.8 CVE-2026-24268 NVIDIA US

· Zero Day Initiative · ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI-26-594: NVIDIA Megatron Bridge load_model_config Code Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Megatron Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24251.

EPSS 0.00 CVSS 7.8 CVE-2026-24251 NVIDIA US

· Zero Day Initiative · ZDI-26-594: NVIDIA Megatron Bridge load_model_config Code Injection Remote Code Execution Vulnerability

1

NVIDIA security advisory (AV26-830)

Serial Number: AV26-830Date: August 19, 2026 As of August 18, 2026, NVIDIA is affected by vulnerabilities in the following products: Triton Inference Server Versions prior to 0.0-26.05 Cumulus Linux GA/LTS Multiple versions NVOS Versions prior to 25.0.2.4438 and 25.0.2.6077 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. product-security/2026/5865 at main · NVIDIA/product-security · GitHub Security…

NVIDIA CA

· Cyber Centre Kanada · NVIDIA security advisory (AV26-830)

1

ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24232.

EPSS 0.00 CVSS 7.8 CVE-2026-24232 NVIDIA US

· Zero Day Initiative · ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

3

ZDI-26-410: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24228.

EPSS 0.00 CVSS 7.8 CVE-2026-24228 NVIDIA US

· Zero Day Initiative · ZDI-26-410: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability

ZDI-26-411: NVIDIA NVTabular Pickle File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NVTabular. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24237.

EPSS 0.00 CVSS 7.8 CVE-2026-24237 NVIDIA US

· Zero Day Initiative · ZDI-26-411: NVIDIA NVTabular Pickle File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability

ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24157.

EPSS 0.01 CVSS 7.8 CVE-2026-24157 NVIDIA US

· Zero Day Initiative · ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability

1

Pwn2Own Berlin 2026 - Day One Results

Welcome to Day One of Pwn2Own Berlin 2026! Today, 22 entries took the Pwn2Own stage to target AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products, as the world’s top security researchers push technology to its limits. Exploits, surprises, and breakthrough discoveries are unfolding.After Day One, we awarded $523,000 for 24 unique 0-days! DEVCORE is currently in the lead for Master of Pwn, but a pack of teams are right on their heels. Stay tuned tomorrow for…

Microsoft OpenAI NVIDIA Oracle US

· ZDI Blog · Pwn2Own Berlin 2026 - Day One Results

1