Status: UPDATED | Advisory ID: CVE-2026-24186
| CVE | CVE-2026-24186 |
| CVSS | CVSS 8.8 (High). |
| Affected products | nvidia nvflare |
| Classified as | CWE-502 (Deserialization of Untrusted Data) |
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-24186 |
| Vendor advisory | https://nvidia.custhelp.com/app/answers/detail/a_id/5819 |