NVIDIA Patches Three High-Severity NeMo Framework Code Injection Flaws
PatchNVIDIA NeMo FrameworkNeMo 2.7.3Our summary
NVIDIA has released an urgent security update for its NeMo Framework, addressing three High-severity code-injection-related flaws: CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228. The issues can enable remote or local code execution depending on the CVE, including potential privilege escalation and data tampering, and affect all NeMo versions from 0.0 up to 2.7.2. Users should upgrade to version 2.7.3 or later to reduce the risk of exploitation, especially on shared training or AI pipeline infrastructure.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.