CVE-2026-24225: NVIDIA Dgx Spark UEFI

Medium severity, CVSS 6.0. EPSS: 0.1% chance of exploitation in the next 30 days.

NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure.

Affected products

  • NVIDIA Dgx Spark UEFI: before 1.110.13 (fixed in 1.110.13)

Published 2026-08-25. Last modified 2026-09-09.