CVE-2026-47626: NVIDIA Dgx Spark UEFI
High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Affected products
- NVIDIA Dgx Spark UEFI: before 1.110.13 (fixed in 1.110.13)
Published 2026-08-25. Last modified 2026-09-09.