PatchSiren cyber security CVE debrief
CVE-2026-24272 NVIDIA CVE debrief
CVE-2026-24272 is a high-severity vulnerability in NVIDIA's TensorRT, potentially leading to code execution via a heap-based buffer overflow. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. NVIDIA TensorRT is a high-performance deep learning inference optimizer and runtime. Successful exploitation of this vulnerability might lead to code execution.
- Vendor
- NVIDIA
- Product
- TensorRT
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-17
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-17
Who should care
Organizations using NVIDIA TensorRT, especially those in industries relying on AI and deep learning, should prioritize patching this vulnerability to prevent potential code execution.
Technical summary
The vulnerability exists in NVIDIA TensorRT, specifically in how it handles memory operations. An attacker could potentially cause a heap-based buffer overflow, leading to code execution. The vulnerability is rated with a CVSS score of 7.8, indicating high severity. The Common Vulnerability Scoring System (CVSS) vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating Local Attack Vector, Low Attack Complexity, No Privileges Needed, User Interaction Required, and High impact on Confidentiality, Integrity, and Availability.
Defensive priority
High
Recommended defensive actions
- Apply the vendor-provided patch or update to a version of TensorRT that addresses this vulnerability.
- Review and update inventory to ensure all instances of TensorRT are identified and patched.
- Implement compensating controls such as monitoring for suspicious activity related to TensorRT.
- Consider restricting access to TensorRT to only those who need it.
- Regularly review and update vulnerability management processes to ensure timely patching of critical vulnerabilities.
Evidence notes
The CVE record was published on 2026-07-14T21:16:44.817Z and was last modified on 2026-07-17T03:28:54.453Z. The NVD entry is currently Analyzed. The vulnerability is described as a heap-based buffer overflow in NVIDIA TensorRT, which could lead to code execution.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24272 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24272
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24272 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24272
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://nvidia.custhelp.com/app/answers/detail/a_id/5855
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.