PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-24201 NVIDIA CVE debrief

NVIDIA vGPU software contains an out-of-bounds access vulnerability in the virtual GPU manager. The issue is rated MEDIUM severity with a CVSS 3.1 score of 5.8 (AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H). A successful exploit could result in data tampering, denial of service, or information disclosure. The vulnerability was published to the NVD on 2026-05-26 and subsequently modified the same day. The root cause is classified as CWE-787 (Out-of-bounds Write). No known exploitation in the wild has been reported, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

Vendor
NVIDIA
Product
Virtual GPU Manager
CVSS
MEDIUM 5.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-05-26
Advisory published
2026-05-26
Advisory updated
2026-05-26

Who should care

Organizations running NVIDIA vGPU software in virtualized environments, particularly those with multi-tenant GPU workloads or shared GPU infrastructure. Cloud service providers and enterprises using NVIDIA GRID or vGPU technologies for virtual desktop infrastructure (VDI) or AI/ML workloads should prioritize patching.

Technical summary

The vulnerability exists in the virtual GPU manager component of NVIDIA vGPU software. The attack requires local access (AV:L) with low privileges (PR:L) and high attack complexity (AC:H). The confidentiality and integrity impacts are low (C:L/I:L) while availability impact is high (A:H), indicating potential for system crashes or service disruption. The scope is unchanged (S:U), meaning the vulnerable component and impacted component are the same.

Defensive priority

medium

Recommended defensive actions

  • Review NVIDIA security bulletin for affected vGPU software versions and apply available patches
  • Restrict local access to systems running NVIDIA vGPU manager to trusted administrators only
  • Monitor for anomalous activity in virtual GPU environments pending patch deployment
  • Verify vGPU driver and manager versions against NVIDIA's security advisory guidance

Evidence notes

The vulnerability description and CVSS vector are sourced from the official NVD entry. The CWE-787 classification and reference links originate from NVIDIA's PSIRT ([email protected]). Vendor attribution to NVIDIA is based on the source email domain and the NVIDIA custhelp.com security bulletin reference.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-24201 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-24201

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-24201 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24201

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.