CVE-2026-24169: NVIDIA Unified Fabric Manager Enterprise - Ga

High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.

NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure.

Affected products

  • NVIDIA Unified Fabric Manager Enterprise - Ga
  • NVIDIA Unified Fabric Manager Enterprise - LTS 2023
  • NVIDIA Unified Fabric Manager Enterprise - LTS 2024
  • NVIDIA Unified Fabric Manager Enterprise - LTS 2025

Published 2026-08-25. Last modified 2026-08-28.