Cyber Security News

Critical NVIDIA Vulnerabilities Enables RCE and DoS Attacks

Critical March 2026 security updates have been released to fix multiple vulnerabilities across enterprise and AI software systems.

The latest advisories highlight severe flaws that could enable attackers to execute arbitrary code, trigger denial-of-service (DoS) conditions, or escalate privileges within compromised systems.

Organizations utilizing NVIDIA’s AI frameworks are strongly urged to review and patch their environments immediately.

The most alarming issue in this patch cycle affects NVIDIA Apex, a popular PyTorch extension for mixed-precision and distributed AI training.

High-Severity AI Infrastructure Risks

Tracked as CVE-2025-33244, this critical-severity vulnerability requires immediate administrative action.

While specific technical exploit paths remain restricted to prevent active abuse, flaws of this severity in AI training environments often pave the way for remote code execution.

Attackers exploiting this could potentially hijack training workloads, steal proprietary AI models, or pivot deeper into enterprise networks.

NVIDIA addressed several high-severity vulnerabilities across its core AI tools, including Triton Inference Server, Megatron LM, NeMo Framework, and Model Optimizer.

Megatron LM faces multiple flaws that could disrupt large-language-model deployments or expose sensitive training data.

Similarly, Triton Inference Server users must patch against CVE-2025-33238 and related vulnerabilities to prevent potential disruptions and unauthorized access to AI model inference pipelines.

March 2026 Vulnerability Summary

The table below lists affected products, severity levels, and CVE IDs from the March 24, 2026, update, enabling security teams to process them more efficiently than before.

ProductSeverityCVE Identifiers
NVIDIA ApexCriticalCVE-2025-33244
Triton Inference ServerHighCVE-2025-33238, CVE-2025-33254, CVE-2026-24158
Model OptimizerHighCVE-2026-24141
NeMo FrameworkHighCVE-2026-24157, CVE-2026-24159
Megatron LMHighCVE-2025-33247, CVE-2025-33248, CVE-2026-24152, CVE-2026-24151, CVE-2026-24150
VIRTIO-Net, SNAP4MediumCVE-2025-33215, CVE-2025-33216
B300 MCUMediumCVE-2025-33242

Following an initiative launched late last year, the NVIDIA Product Security Incident Response Team (PSIRT) now publishes these bulletins on GitHub alongside traditional web alerts.

The data is provided in Markdown and CSAF formats, enabling automated systems to quickly ingest CVE information for faster response.

Administrators should review the full NVIDIA Security Bulletins for March 2026 and apply the recommended software package updates without delay.

Organizations running affected AI frameworks, network components, and MCU hardware must prioritize these patches to defend their infrastructure against emerging remote access and DoS threats.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

2 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

8 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

18 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago