ZeroHour

CVE-2026-61772

niche

Unsafe Deserialization in NVIDIA Megatron Bridge Enables Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

NVIDIA Megatron Bridge, a framework in the NVIDIA NeMo ecosystem used for training and fine-tuning large language models, contains a deserialization of untrusted data flaw (CWE-502). Per the CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N), a local attacker with limited privileges can trigger the flaw by getting the software to deserialize crafted untrusted data, with no user interaction required. A successful exploit may lead to arbitrary code execution, tampering with data, and disclosure of sensitive information, with high impact on confidentiality, integrity, and availability. Potentially affected are environments running Megatron Bridge, such as AI engineering workstations, notebooks, and training clusters, though local access with limited privileges is required to exploit it. There is no known exploitation so far: no public proof-of-concept exists, the issue is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days.

What to do: Check NVIDIA's PSIRT security advisory for the exact affected version range and upgrade Megatron Bridge to the fixed release it specifies, since fixed versions are not given in the source data. Until patching, avoid deserializing untrusted inputs such as checkpoints, pickled artifacts, or serialized job data from untrusted sources, and restrict local access to systems running Megatron Bridge. Given the high severity rating but absence of known exploitation and low EPSS, treat this as a standard priority patch rather than an emergency, and monitor NVIDIA advisories for updates.

Affected
NVIDIA NeMo Megatron Bridge
Estimated exposure
nichelikely on the order of thousands to low tens of thousands of users/environments (no public install counts) — Megatron Bridge is a specialized, recently introduced LLM-training framework used by AI engineering teams on workstations and training clusters rather than deployed at internet scale, and no public install or scan counts are available, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendors
nvidia
Products
nemo megatron bridge
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.