CVE-2026-24186: NVIDIA Nvflare
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.
Affected products
- NVIDIA Nvflare: before 2.7.2 (fixed in 2.7.2)
Published 2026-04-28. Last modified 2026-06-17.