
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24157 is a deserialization of untrusted data vulnerability in the NVIDIA NeMo Framework's checkpoint loading functionality that enables remote code execution. It affects all versions of NVIDIA NeMo prior to 2.6.2. The vulnerability was disclosed on March 24, 2026, with a patch released shortly after. NVD assigned a CVSS v3.1 base score of 9.8 (Critical), while NVIDIA's own CNA scoring assigned 7.8 (High) using a local attack vector (Feedly, NVIDIA Advisory).
The root cause is improper deserialization of untrusted data (CWE-502) during checkpoint loading in the NVIDIA NeMo Framework, a toolkit used for building large-scale AI and machine learning models. An attacker can supply a maliciously crafted checkpoint file that, when loaded by the framework, triggers arbitrary code execution through unsafe deserialization — a technique mapped to CAPEC-586 (Object Injection). NVD's analysis assigns a network-based attack vector with no privileges or user interaction required, though NVIDIA's own scoring reflects a local attack vector, suggesting exploitation may depend on how checkpoint files are ingested (e.g., via network-accessible model repositories or APIs) (Feedly, NVIDIA Advisory).
Successful exploitation can result in remote code execution, escalation of privileges, information disclosure, and data tampering on systems running vulnerable versions of NVIDIA NeMo Framework. Given that NeMo is commonly deployed in AI/ML training and inference pipelines — often with access to sensitive model weights, datasets, and infrastructure — a compromise could expose proprietary data and enable lateral movement within the broader environment. The vulnerability requires no user interaction and no prior privileges under NVD's assessment, making it highly impactful in exposed deployments (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.116%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported.
.nemo, .ckpt, .pkl) in model directories; newly created scripts or binaries in NeMo working directories.bash, sh, curl, wget, python -c); unexpected network connections initiated by the NeMo process.NVIDIA has released a patch in NeMo Framework version 2.6.2, and all users should upgrade immediately (NVIDIA Advisory). Organizations unable to patch immediately should restrict network access to systems running NeMo Framework, implement strict allowlisting and integrity verification (e.g., cryptographic signatures) for checkpoint files, and avoid loading checkpoints from untrusted or unverified sources. As a last resort, consider isolating affected NeMo deployments from untrusted network sources or disabling checkpoint loading functionality until patching is feasible (Feedly).
Security news outlets including GBHackers, CyberPress, and CyberSecurityNews covered the vulnerability as part of broader reporting on critical NVIDIA AI framework vulnerabilities enabling RCE and DoS attacks (GBHackers, CyberPress, CyberSecurityNews). Social media activity was noted on Bluesky and Mastodon shortly after disclosure. Red Hat also tracked the vulnerability given its relevance to AI/ML workloads running on Red Hat platforms (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."