CVE-2025-33181: NVIDIA Cumulus Linux

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.

Affected products

  • NVIDIA Cumulus Linux: before 5.14.0 (fixed in 5.14.0); from 5.9.0, before 5.9.4 (fixed in 5.9.4); from 5.11.0, before 5.11.4 (fixed in 5.11.4)
  • NVIDIA Nvos: before 25.02.2452 (fixed in 25.02.2452); before 25.02.4282 (fixed in 25.02.4282); before 25.02.5030 (fixed in 25.02.5030)

Published 2026-02-24. Last modified 2026-06-17.