Junglewise Threat Intelligence

CVE-2026-61760: NVIDIA Megatron Bridge unsafe deserialization

CVE-2026-61760 · Severity: high · CVSS 7.8 · Published 2026-09-01

Technologies: Nvidia Nemo Megatron Bridge, Nvidia Megatron-Bridge. Vendors: Nvidia.

Executive brief

NVIDIA Megatron Bridge is a library used for distributed training and inference of large language models. An attacker can trigger unsafe deserialization of untrusted data, leading to arbitrary code execution, data theft, or modification of model data.

Technical details

The vulnerability is a classic unsafe deserialization flaw in NVIDIA Megatron Bridge. An attacker can supply malicious serialized data that, when deserialized by the application, executes arbitrary code. The attack requires network access to an interface accepting serialized input, or the ability to supply malicious serialized data to a vulnerable process. A successful exploit grants full code execution in the context of the affected service, potentially compromising model integrity, training data, and the host system. Patch availability should be confirmed with NVIDIA.

Affected products

  • NVIDIA Megatron Bridge

Timeline

  • 2026-09-01: disclosed

References

Related threats