CVE-2026-24262: NVIDIA Dgx Spark UEFI

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

Affected products

  • NVIDIA Dgx Spark UEFI: before 1.110.13 (fixed in 1.110.13)

Published 2026-08-25. Last modified 2026-09-09.