NVIDIA FLARE SDK: Unauthenticated remote code execution
CVSS 9.8CVE-2026-24178NVIDIA / GPU stackcurated
Impact
Unauthenticated remote code execution
Who can reach it
Network-adjacent unauthenticated
What to do
Emergency upgrade of FLARE; redeploy federated-learning services
References
Related entries
- NVIDIA FLARE SDK: RCE via unsafe deserialization in message handlingCVE-2026-24186 · NVIDIA FLARE SDKHigh
- NVIDIA FLARE SDK: Auth bypass via insufficient input validationCVE-2026-24204 · NVIDIA FLARE SDKMedium
- Triton Inference Server: Missing authenticationCVE-2026-24207 · Triton Inference ServerCritical
- NVIDIA Dynamo: Unauthenticated remote code executionCVE-2026-24254 · NVIDIA DynamoCritical
- NVIDIA AIStore: Missing authentication on API endpointsCVE-2026-24270 · NVIDIA AIStoreCritical
- NVIDIA Triton Inference Server: A path traversal scored 9.8 (network, no privileges, fullCVE-2026-47627 · NVIDIA Triton Inference ServerCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.