PatchSiren cyber security CVE debrief
CVE-2026-24201 NVIDIA CVE debrief
NVIDIA vGPU software contains an out-of-bounds access vulnerability in the virtual GPU manager. The issue is rated MEDIUM severity with a CVSS 3.1 score of 5.8 (AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H). A successful exploit could result in data tampering, denial of service, or information disclosure. The vulnerability was published to the NVD on 2026-05-26 and subsequently modified the same day. The root cause is classified as CWE-787 (Out-of-bounds Write). No known exploitation in the wild has been reported, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- NVIDIA
- Product
- Virtual GPU Manager
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
Organizations running NVIDIA vGPU software in virtualized environments, particularly those with multi-tenant GPU workloads or shared GPU infrastructure. Cloud service providers and enterprises using NVIDIA GRID or vGPU technologies for virtual desktop infrastructure (VDI) or AI/ML workloads should prioritize patching.
Technical summary
The vulnerability exists in the virtual GPU manager component of NVIDIA vGPU software. The attack requires local access (AV:L) with low privileges (PR:L) and high attack complexity (AC:H). The confidentiality and integrity impacts are low (C:L/I:L) while availability impact is high (A:H), indicating potential for system crashes or service disruption. The scope is unchanged (S:U), meaning the vulnerable component and impacted component are the same.
Defensive priority
medium
Recommended defensive actions
- Review NVIDIA security bulletin for affected vGPU software versions and apply available patches
- Restrict local access to systems running NVIDIA vGPU manager to trusted administrators only
- Monitor for anomalous activity in virtual GPU environments pending patch deployment
- Verify vGPU driver and manager versions against NVIDIA's security advisory guidance
Evidence notes
The vulnerability description and CVSS vector are sourced from the official NVD entry. The CWE-787 classification and reference links originate from NVIDIA's PSIRT ([email protected]). Vendor attribution to NVIDIA is based on the source email domain and the NVIDIA custhelp.com security bulletin reference.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24201 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24201
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24201 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24201
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://nvidia.custhelp.com/app/answers/detail/a_id/5821
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.