CVE-2026-24186: NVIDIA Nvflare

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.

Affected products

  • NVIDIA Nvflare: before 2.7.2 (fixed in 2.7.2)

Published 2026-04-28. Last modified 2026-06-17.