Junglewise Threat Intelligence

CVE-2026-24262: NVIDIA DGX Spark out-of-bounds write in system firmware

CVE-2026-24262 · Severity: high · CVSS 8.2 · Published 2026-08-25

Technologies: Nvidia Dgx Spark Uefi, Nvidia Dgx Spark. Vendors: Nvidia.

Executive brief

NVIDIA DGX Spark is a high-performance AI computing system used for machine learning and data center workloads. A vulnerability in its system firmware could allow a privileged attacker to corrupt memory, potentially leading to unauthorized code execution, system crashes, or data tampering. This poses a significant risk to organizations relying on DGX Spark for mission-critical AI infrastructure.

Technical details

The vulnerability is an out-of-bounds write flaw in NVIDIA DGX Spark's system firmware. It requires an attacker with elevated privileges to exploit. A successful exploit can lead to code execution, privilege escalation, denial of service, information disclosure, and data tampering. The vulnerability affects the firmware component directly, making it a low-level system issue. Patches are expected from NVIDIA as part of their security update cycle.

Affected products

  • NVIDIA DGX Spark <UNKNOWN>

Timeline

  • 2026-08-25: disclosed
  • other: Not reported as exploited in the wild as of publication date

References

Related threats