ZeroHour

Vulnerabilities

95 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-61753
Deserialization of Untrusted Data in NVIDIA Megatron Bridge (potential RCE)

NVIDIA Megatron Bridge, NVIDIA's open-source library for post-training and fine-tuning large language models (part of the NeMo ecosystem), contains a vulnerability in which deserialization of untrusted data can be exploited (CWE-502, with CWE-22 path traversal also cited). The CVSS vector (AV:L/PR:L/UI:N) indicates exploitation requires local access with low privileges and no user interaction, most plausibly triggered when the library deserializes attacker-controlled input such as checkpoints or other serialized training artifacts loaded from an untrusted source. A successful exploit could result in arbitrary code execution, tampering with data, and disclosure of sensitive information on the affected system. Only environments using NVIDIA Megatron Bridge (e.g., ML development, fine-tuning, and training workflows) are affected; no specific affected version ranges were provided in the source data. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days (30th percentile), indicating low near-term exploitation risk.

Do: Consult NVIDIA's security bulletin for CVE-2026-61753 to identify the affected and fixed Megatron Bridge versions, and upgrade to the fixed release as soon as practical. Until patched, only load checkpoints and other serialized artifacts from trusted sources and avoid deserializing untrusted or third-party model files in lower-trust environments. Given the local attack vector and low EPSS score, treat this as routine patching rather than an emergency, but monitor NVIDIA and community channels for a public PoC or in-the-wild exploitation.

7.8<1%
  • NVIDIA NeMo Megatron Bridge
nichelow thousands of ML developer/training environments (specialized open-source LLM fine-tuning library; not typically internet-exposed)
CVE-2026-65098
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.

NVD description · AI analysis pending
9.8
group max
<1%
  • nvidia nemoclaw
CVE-2026-65083
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs.

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.

NVD description · AI analysis pending
9.9
group max
<1%
  • nvidia openshell
CVE-2026-47626
+1 in the same advisory: …47624
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write.

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

NVD description · AI analysis pending
8.2
group max
<1%
  • nvidia dgx spark uefi