CVE Tools
Back to feed
Patch released NVIDIA NeMo Framework ai-ml NeMo 2.7.3 NVIDIA rce

NVIDIA Patches Three High-Severity NeMo Framework Code Injection Flaws

Daily CyberSecurity (securityonline.info)·By Do Son··1 min read
CVE Tools coverage

NVIDIA has released an urgent security update for its NeMo Framework, addressing three High-severity code-injection-related flaws: CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228. The issues can enable remote or local code execution depending on the CVE, including potential privilege escalation and data tampering, and affect all NeMo versions from 0.0 up to 2.7.2. Users should upgrade to version 2.7.3 or later to reduce the risk of exploitation, especially on shared training or AI pipeline infrastructure.