logo

NVIDIA FLARE Alert: Critical SDK Vulnerabilities Open Doors to Full System Takeover

ID: 642d52a1-6e00-5d6f-ab22-6716fad28cbb

STIX ID: report--642d52a1-6e00-5d6f-ab22-6716fad28cbb

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Ddos

...
...

NVIDIA released an urgent security advisory for the NVIDIA FLARE SDK (affecting Linux and macOS) that fixes multiple vulnerabilities—most notably CVE-2026-24178, a critical (CVSS 9.8) authentication bypass in the NVFlare Dashboard enabling privilege escalation, data tampering, code execution and DoS; plus a high-severity deserialization RCE (CVE-2026-24186) and a medium-severity path-traversal information disclosure (CVE-2026-24204). Users and developers are strongly advised to update to NVFlare SDK v2.7.2 or later via the NVIDIA/NVFlare GitHub repository immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.