Vulnerability Details CVE-2026-24263
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 9.1%
CVSS Severity
CVSS v3 Score 8.2
Products affected by CVE-2026-24263
-
cpe:2.3:h:nvidia:dgx_spark:-
-
cpe:2.3:o:nvidia:dgx_spark_uefi:-
-
cpe:2.3:o:nvidia:dgx_spark_uefi:1.110.12