NVIDIA: 25 Vulnerabilities in NemoClaw, OpenShell, DGX Spark, and UFM Enterprise Disclosed Together
Key findings • 25 vulnerabilities disclosed in a single batch on August 25, 2026, affecting NVIDIA NemoClaw, OpenShell, DGX Spark, and UFM Enterprise. • Multiple OS command injection flaws fo…

Key findings
- 25 vulnerabilities disclosed in a single batch on August 25, 2026, affecting NVIDIA NemoClaw, OpenShell, DGX Spark, and UFM Enterprise.
- Multiple OS command injection flaws found in NVIDIA NemoClaw, posing risks of code execution and data tampering.
- Critical sandbox escape vulnerability (CVE-2026-65093) identified in NVIDIA OpenShell.
- NVIDIA DGX Spark system firmware impacted by high-severity flaws including out-of-bounds writes and NULL pointer dereferences.
- CVE-2026-65105 in NemoClaw allows potential hijacking of AI agents through a single website visit.
- NVIDIA has released patches; users are urged to update promptly.
On August 25, 2026, NVIDIA disclosed a significant batch of 25 vulnerabilities affecting various products including NemoClaw, OpenShell, DGX Spark, and UFM Enterprise. These vulnerabilities, disclosed within a four-hour window, range in severity from Medium to Critical, with several carrying high CVSS scores. The disclosures highlight potential risks including unauthenticated access, OS command injection, sandbox escapes, and privilege escalation, underscoring the need for prompt patching and security review by users of these NVIDIA products.
Several vulnerabilities cluster around NVIDIA NemoClaw for Linux, with multiple instances of OS command injection. CVE-2026-65099, CVE-2026-65096, CVE-2026-65090, and CVE-2026-65089 all detail OS command injection flaws within different components of NemoClaw, including its command-line interface, Telegram bridge, NIM management, and status/logs plugins. These could lead to code execution, data tampering, information disclosure, and denial of service. Additionally, CVE-2026-65105 and CVE-2026-65098 present risks of unauthenticated access and weak authentication, respectively, potentially leading to information disclosure and denial of service. CVE-2026-65097 involves a download of code without integrity check during installation, and CVE-2026-65081 concerns the execution of untrusted code during the installation process, both carrying risks of code execution and privilege escalation. CVE-2026-65084 points to improper certificate validation in the deployment process, and CVE-2026-65082 describes code injection in the migration command, both with severe potential impacts. Medium severity issues like CVE-2026-65088 (invocation of process using sensitive information) and CVE-2026-65087 (insufficiently protected credentials) also contribute to the overall risk profile.
NVIDIA OpenShell and its related components are also affected by multiple vulnerabilities. CVE-2026-65093, a critical vulnerability, allows for a sandbox escape, potentially leading to code execution and privilege escalation. CVE-2026-65091 describes an OS command injection flaw in a malicious gateway, while CVE-2026-65086 details an OS command injection in the sandbox exec handler. Path traversal bypass in the OpenShell Sandbox is addressed by CVE-2026-65092, and improper encoding in the inference proxy is noted in CVE-2026-65085. CVE-2026-65083, another critical vulnerability, involves an incomplete list of disallowed inputs in the sandbox provisioning API, with wide-ranging impacts.
The NVIDIA DGX Spark platform is impacted by several system firmware vulnerabilities. CVE-2026-47626, CVE-2026-24262, and CVE-2026-24263 all involve out-of-bounds writes or NULL pointer dereferences in the system firmware, potentially leading to code execution, privilege escalation, and denial of service. CVE-2026-47624, a medium severity vulnerability in UEFI, allows a privileged local user to bypass administrator password protection. Additionally, CVE-2026-24225 describes an out-of-bounds read in the standalone MM firmware, potentially leading to information disclosure.
NVIDIA UFM Enterprise faces vulnerabilities in its web interface and plugin management API. CVE-2026-24170 allows improper authentication via specially crafted HTTP requests, potentially leading to code execution and privilege escalation. CVE-2026-24169 involves code injection through the plugin management API by an authenticated user, also with risks of code execution and privilege escalation.
The disclosure of CVE-2026-65105 in NVIDIA NemoClaw has been highlighted by cybersecurity news outlets, noting its potential to allow attackers to hijack AI agents with a single website visit. This specific vulnerability, when exploited, can expose the local Ollama model server used by NemoClaw, enabling persistent poisoning of the AI model's behavior. The vulnerability arises from how NemoClaw configures Ollama, setting OLLAMA_HOST=0.0.0.0:11434 to allow communication between an OpenShell Docker container and the host's Ollama service, inadvertently making Ollama listen on all interfaces.
NVIDIA has released patches and advisories for these vulnerabilities. Users are strongly advised to consult NVIDIA's official security bulletins for specific version information and recommended mitigation steps. Prompt application of these updates is crucial to protect against the identified risks, which span across multiple product lines and impact core functionalities such as AI model deployment, system security, and network management.
This coordinated disclosure event underscores the importance of staying current with security updates for NVIDIA products. The breadth of affected components and the severity of the vulnerabilities, including critical sandbox escapes and command injection flaws, necessitate a thorough review of deployed systems. Users should prioritize patching and verify system configurations to prevent potential exploitation, particularly in environments utilizing AI and machine learning workloads managed by NemoClaw or OpenShell.
The batch of vulnerabilities disclosed on August 25, 2026, impacts NVIDIA NemoClaw, OpenShell, DGX Spark, and UFM Enterprise. Multiple OS command injection vulnerabilities were found across various NemoClaw components. A critical sandbox escape vulnerability (CVE-2026-65093) affects NVIDIA OpenShell. NVIDIA DGX Spark system firmware has several high-severity flaws, including out-of-bounds writes and NULL pointer dereferences. CVE-2026-65105 in NemoClaw has been highlighted for its potential to hijack AI agents via a malicious website. NVIDIA has released security advisories and patches for the affected products. CVE-2026-65105, CVE-2026-65099, CVE-2026-65098, CVE-2026-65097, CVE-2026-65096, CVE-2026-65093, CVE-2026-65092, CVE-2026-65091, CVE-2026-65090, CVE-2026-65089, CVE-2026-65088, CVE-2026-65087, CVE-2026-65086, CVE-2026-65085, CVE-2026-65084, CVE-2026-65083, CVE-2026-65082, CVE-2026-65081, CVE-2026-47626, CVE-2026-47624, CVE-2026-24263, CVE-2026-24262, CVE-2026-24225, CVE-2026-24170, CVE-2026-24169