Back Heise.De Nvidia's AI agent platform NeMo is vulnerable via three security flaws
Nvidia NeMo for handling AI agents is vulnerable on all platforms. In a current version, the developers have now closed a total of three security vulnerabilities. So far, there are no indications from the company that attackers are already exploiting the vulnerabilities.
In a warning message , the vulnerabilities (CVE-2026-24155, CVE-2026-24252, CVE-2026-24228) are classified with the threat level “ high. ” In all three cases, attackers can manipulate data, access protected information, gain higher user privileges, and even execute malicious code after successful attacks. How such attacks can proceed in detail is not yet known.
The developers state that they have closed the vulnerabilities in NeMo Framework 2.7.3 . All versions are said to be vulnerable.
Most recently, the developers closed security vulnerabilities in AI tools in April .
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
