NVIDIA FLARE Alert: Critical SDK Vulnerabilities Open Doors to Full System Takeover
ID: 642d52a1-6e00-5d6f-ab22-6716fad28cbb
STIX ID: report--642d52a1-6e00-5d6f-ab22-6716fad28cbb
Feed Name: securityonline.info
NVIDIA released an urgent security advisory for the NVIDIA FLARE SDK (affecting Linux and macOS) that fixes multiple vulnerabilities—most notably CVE-2026-24178, a critical (CVSS 9.8) authentication bypass in the NVFlare Dashboard enabling privilege escalation, data tampering, code execution and DoS; plus a high-severity deserialization RCE (CVE-2026-24186) and a medium-severity path-traversal information disclosure (CVE-2026-24204). Users and developers are strongly advised to update to NVFlare SDK v2.7.2 or later via the NVIDIA/NVFlare GitHub repository immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
