NVIDIA vulnerabilities
16 CVEs tracked
In this reporting period, NVIDIA is primarily seen in the context of open-source AI security initiatives and product vulnerabilities. The company spearheaded the 'Open Secure AI Alliance' and open-sourced the NOOA framework for auditing AI agents. Security researchers targeted NVIDIA products at 'Pwn2Own Berlin 2026', while a critical double-free vulnerability (CVE-2026-64832) was discovered in the NVIDIA NVDEC decoder within FFmpeg. Defenders should prioritize applying available patches, especially for NVIDIA NeMo (CVE-2026-24252), Dynamo (CVE-2026-24253, CVE-2026-24254), and Cumulus Linux (CVE-2026-24183, CVE-2026-24184), and follow NOOA's security isolation requirements for running model-generated code.
Azərbaycanca: Hesabat dövründə NVIDIA əsasən açıq mənbəli AI təhlükəsizliyi təşəbbüsləri və məhsul zəiflikləri kontekstində görünür. Şirkət 'Open Secure AI Alliance' qrupunun qurulmasına rəhbərlik edib və AI agentlərinin test edilməsi üçün NOOA framework-ni açıq mənbə kimi təqdim edib. Təhlükəsizlik tədqiqatçıları 'Pwn2Own Berlin 2026' çərçivəsində NVIDIA məhsullarını hədəf almış, eyni zamanda FFmpeg-in NVIDIA NVDEC dekoderində kritik CVE-2026-64832 (double-free) zəifliyi aşkarlanmışdır. Müdafiəçilər, xüsusilə NVIDIA NeMo (CVE-2026-24252), Dynamo (CVE-2026-24253, CVE-2026-24254) və Cumulus Linux (CVE-2026-24183, CVE-2026-24184) üçün buraxılmış yamaları tətbiq etməli və NOOA framework-nin təhlükəsiz izolyasiya tələblərinə diqqət yetirməlidir.
This vendor's CVEs16
- CVE-2026-64832EPSS 0.34%
- CVE-2026-47630EPSS 0.21%
- CVE-2026-47629EPSS 0.39%
- CVE-2026-47628EPSS 0.39%
- CVE-2026-47627EPSS 0.46%
- CVE-2026-47612EPSS 0.55%
- CVE-2026-47606EPSS 0.41%
- CVE-2026-47487EPSS 0.18%
- CVE-2026-47483EPSS 0.31%
- CVE-2026-24255EPSS 0.38%
- CVE-2026-24254EPSS 0.54%
- CVE-2026-24253EPSS 0.35%
- CVE-2026-24252EPSS 0.69%
- CVE-2026-24185EPSS 0.21%
- CVE-2026-24184EPSS 0.29%
- CVE-2026-24183EPSS 0.13%
This hub is built from skopnix's own reporting on NVIDIA: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.