# NVIDIA vulnerabilities & exploitation

> As of 2026-10-10, Threadlinqs tracks 35 NVIDIA CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 9 tracked threat campaigns and 1 named threat actor.

**Data as of:** 2026-10-10

## Exploitation timeline

Threadlinqs has recorded 35 NVIDIA CVEs published between 2026-07-15 and 2026-08-15. The busiest month was 2026-08 (33 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 35 of 35 tracked NVIDIA CVEs.

- [CVE-2026-65091](https://intel.threadlinqs.com/cve/CVE-2026-65091) — HIGH 8.8 · EPSS 2.6% · 2026-08-25
- [CVE-2026-65086](https://intel.threadlinqs.com/cve/CVE-2026-65086) — MEDIUM 6.8 · EPSS 2.4% · 2026-08-25
- [CVE-2026-65089](https://intel.threadlinqs.com/cve/CVE-2026-65089) — HIGH 7.8 · EPSS 1.3% · 2026-08-25
- [CVE-2026-65090](https://intel.threadlinqs.com/cve/CVE-2026-65090) — HIGH 7.8 · EPSS 1.3% · 2026-08-25
- [CVE-2026-65096](https://intel.threadlinqs.com/cve/CVE-2026-65096) — HIGH 7.8 · EPSS 1.3% · 2026-08-25
- [CVE-2026-65099](https://intel.threadlinqs.com/cve/CVE-2026-65099) — HIGH 7.8 · EPSS 1.3% · 2026-08-25
- [CVE-2026-65098](https://intel.threadlinqs.com/cve/CVE-2026-65098) — HIGH 8.1 · EPSS 1% · 2026-08-25
- [CVE-2026-24168](https://intel.threadlinqs.com/cve/CVE-2026-24168) — MEDIUM 6.8 · EPSS 1% · 2026-08-25
- [CVE-2026-65083](https://intel.threadlinqs.com/cve/CVE-2026-65083) — CRITICAL 9.9 · EPSS 0.9% · 2026-08-25
- [CVE-2026-65093](https://intel.threadlinqs.com/cve/CVE-2026-65093) — CRITICAL 9.9 · EPSS 0.8% · 2026-08-25
- [CVE-2026-47627](https://intel.threadlinqs.com/cve/CVE-2026-47627) — CRITICAL 9.8 · EPSS 0.7% · 2026-08-18
- [CVE-2026-65092](https://intel.threadlinqs.com/cve/CVE-2026-65092) — HIGH 8.5 · EPSS 0.6% · 2026-08-25
- [CVE-2026-47483](https://intel.threadlinqs.com/cve/CVE-2026-47483) — HIGH 8.2 · EPSS 0.6% · 2026-07-28
- [CVE-2026-65084](https://intel.threadlinqs.com/cve/CVE-2026-65084) — HIGH 8.1 · EPSS 0.5% · 2026-08-25
- [CVE-2026-65105](https://intel.threadlinqs.com/cve/CVE-2026-65105) — HIGH 8.1 · EPSS 0.5% · 2026-08-25
- [CVE-2026-65081](https://intel.threadlinqs.com/cve/CVE-2026-65081) — HIGH 8.1 · EPSS 0.4% · 2026-08-25
- [CVE-2026-24169](https://intel.threadlinqs.com/cve/CVE-2026-24169) — HIGH 8 · EPSS 0.4% · 2026-08-25
- [CVE-2025-23351](https://intel.threadlinqs.com/cve/CVE-2025-23351) — CRITICAL 9 · EPSS 0.4% · 2026-07-01
- [CVE-2026-24170](https://intel.threadlinqs.com/cve/CVE-2026-24170) — HIGH 8.8 · EPSS 0.3% · 2026-08-25
- [CVE-2026-65097](https://intel.threadlinqs.com/cve/CVE-2026-65097) — HIGH 7.5 · EPSS 0.3% · 2026-08-25
- [CVE-2026-24184](https://intel.threadlinqs.com/cve/CVE-2026-24184) — HIGH 7.5 · EPSS 0.3% · 2026-08-18
- [CVE-2026-24185](https://intel.threadlinqs.com/cve/CVE-2026-24185) — HIGH 7.1 · EPSS 0.3% · 2026-08-18
- [CVE-2026-24167](https://intel.threadlinqs.com/cve/CVE-2026-24167) — MEDIUM 6.8 · EPSS 0.3% · 2026-08-25
- [CVE-2026-47487](https://intel.threadlinqs.com/cve/CVE-2026-47487) — MEDIUM 4.4 · EPSS 0.2% · 2026-08-04
- [CVE-2026-65082](https://intel.threadlinqs.com/cve/CVE-2026-65082) — HIGH 7 · EPSS 0.2% · 2026-08-25
- [CVE-2026-47626](https://intel.threadlinqs.com/cve/CVE-2026-47626) — HIGH 8.2 · EPSS 0.2% · 2026-08-25
- [CVE-2026-47624](https://intel.threadlinqs.com/cve/CVE-2026-47624) — MEDIUM 6 · EPSS 0.2% · 2026-08-25
- [CVE-2026-65088](https://intel.threadlinqs.com/cve/CVE-2026-65088) — MEDIUM 5.5 · EPSS 0.2% · 2026-08-25
- [CVE-2026-65085](https://intel.threadlinqs.com/cve/CVE-2026-65085) — MEDIUM 5.2 · EPSS 0.2% · 2026-08-25
- [CVE-2026-24263](https://intel.threadlinqs.com/cve/CVE-2026-24263) — HIGH 8.2 · EPSS 0.2% · 2026-08-25
- [CVE-2026-24262](https://intel.threadlinqs.com/cve/CVE-2026-24262) — HIGH 8.2 · EPSS 0.2% · 2026-08-25
- [CVE-2026-65087](https://intel.threadlinqs.com/cve/CVE-2026-65087) — MEDIUM 5.6 · EPSS 0.2% · 2026-08-25
- [CVE-2026-24225](https://intel.threadlinqs.com/cve/CVE-2026-24225) — MEDIUM 6 · EPSS 0.1% · 2026-08-25
- [CVE-2026-24183](https://intel.threadlinqs.com/cve/CVE-2026-24183) — HIGH 7.8 · EPSS 0.1% · 2026-08-18
- [CVE-2026-24166](https://intel.threadlinqs.com/cve/CVE-2026-24166) — MEDIUM 5.1 · EPSS 0.1% · 2026-08-25

## Products affected

Threadlinqs normalises CPE and CNA product records across all 35 CVEs; 23 distinct NVIDIA products are affected. The most frequently affected (top 20):

- NemoClaw — 12 CVEs
- OpenShell — 6 CVEs
- DGX Spark — 5 CVEs
- Unified Fabric Manager Enterprise - GA — 5 CVEs
- Unified Fabric Manager Enterprise - LTS 2023 — 5 CVEs
- Unified Fabric Manager Enterprise - LTS 2024 — 5 CVEs
- Unified Fabric Manager Enterprise - LTS 2025 — 5 CVEs
- Cumulus Linux GA — 2 CVEs
- Triton Inference Server — 2 CVEs
- BlueField GA — 1 CVE
- BlueField LTS22 — 1 CVE
- BlueField LTS23 — 1 CVE
- BlueField LTS24 — 1 CVE
- ConnectX GA — 1 CVE
- ConnectX LTS22 — 1 CVE
- ConnectX LTS23 — 1 CVE
- ConnectX LTS24 — 1 CVE
- ConnectX-4 — 1 CVE
- ConnectX-4 LX — 1 CVE
- Cumulus Linux LTS — 1 CVE

## Threat activity

9 tracked threat campaigns reference NVIDIA products or exploit NVIDIA CVEs:

- [Nvidia DCGM Exporter unauthenticated denial-of-service via /debug/pprof (CVE-2026-47483)](https://intel.threadlinqs.com/threat/TL-2026-3057) — HIGH — 2026-10-08
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL — 2026-08-26
- [NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent Skills](https://intel.threadlinqs.com/threat/TL-2026-1828) — LOW — 2026-08-03
- [CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1812) — CRITICAL — 2026-08-01
- [Bit2Watt: Synchronized GPU Power-Oscillation Attack Could Let Cloud Tenants Destabilize Power Grids](https://intel.threadlinqs.com/threat/TL-2026-1598) — HIGH — 2026-07-21
- [Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red Hat Linux, and Anthropic Claude Code](https://intel.threadlinqs.com/threat/TL-2026-1546) — HIGH — 2026-07-19
- [LabubaRAT: Rust-based RAT Disguised as NVIDIA Container Runtime Toolkit](https://intel.threadlinqs.com/threat/TL-2026-1401) — HIGH — 2026-07-15
- [Pwn2Own Berlin 2026 Day Two: Microsoft Exchange RCE-as-SYSTEM Chain and 14 Other Zero-Days Disclosed](https://intel.threadlinqs.com/threat/TL-2026-1547) — HIGH — 2026-05-15
- [NVIDIA GeForce NOW Armenian Data Breach via GFN.am Alliance Partner Compromise — ShinyHunters-Branded PII Theft](https://intel.threadlinqs.com/threat/TL-2026-0485) — HIGH — 2026-05-08

## Threat actors targeting NVIDIA

Named threat actors attributed to campaigns that involve NVIDIA products or CVEs, with the number of linked campaigns:

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1 campaign

## How to prioritise NVIDIA patching

This order follows the data Threadlinqs holds for NVIDIA, not a generic severity checklist:

- No NVIDIA CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-65091](https://intel.threadlinqs.com/cve/CVE-2026-65091) (2.6%), [CVE-2026-65086](https://intel.threadlinqs.com/cve/CVE-2026-65086) (2.4%), [CVE-2026-65089](https://intel.threadlinqs.com/cve/CVE-2026-65089) (1.3%).
- 4 CVEs score Critical and 21 High on CVSS v3 (maximum 9.9, average 7.5); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-10 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/nvidia
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
