Junglewise Threat Intelligence

CVE-2026-65111: NVIDIA NeMo Speech code injection vulnerability

CVE-2026-65111 · Severity: high · CVSS 7.8 · Published 2026-09-22

Technologies: Nvidia Nemo Speech. Vendors: Nvidia.

Executive brief

NVIDIA NeMo Speech is a framework for building speech recognition and synthesis applications. Malicious input can trigger code injection, potentially allowing an attacker to execute arbitrary code, access sensitive data, or modify stored information on affected systems.

Technical details

The vulnerability is a code injection flaw in NVIDIA NeMo Speech that can be triggered via malicious input on all supported platforms. Exploitation allows remote code execution, information disclosure, and data tampering without requiring authentication or special privileges. Patches are expected from NVIDIA through their security bulletin process.

Affected products

  • NVIDIA NeMo Speech all platforms

Timeline

  • 2026-09-22: disclosed

References

Related threats