CVE-2026-24168: NVIDIA Unified Fabric Manager Enterprise - Ga

Medium severity, CVSS 6.8. EPSS: 1% chance of exploitation in the next 30 days.

NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API requests. A successful exploit of this vulnerability may lead to code execution, escalation of privileges and information disclosure.

Affected products

  • NVIDIA Unified Fabric Manager Enterprise - Ga
  • NVIDIA Unified Fabric Manager Enterprise - LTS 2023
  • NVIDIA Unified Fabric Manager Enterprise - LTS 2024
  • NVIDIA Unified Fabric Manager Enterprise - LTS 2025

Published 2026-08-25. Last modified 2026-08-28.