SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-24166

MEDIUM · CVSS 5.1 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

NVIDIA UFM Enterprise is vulnerable due to a flaw in its session management component, allowing attackers to leverage a hard-coded cryptographic key to extract sensitive information. Exploitation of this vulnerability could result in information disclosure and potential privilege escalation. Organizations using this software should prioritize remediation to mitigate risks associated with unauthorized access and data leakage.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-24166
Severity
MEDIUM
CVSS
5.1
EPSS
0.15%

Original NVD Description

NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges.