Cvefeed Multiple CVEs Discovered in NVIDIA Megatron and Other Products
Article Content
- •CVE-2025-33248 allows RCE in NVIDIA Megatron-LM through malicious files.
- •CVE-2026-33336 involves code injection but lacks specific product details.
- •Both vulnerabilities are currently unpatched and pose significant risks.
On March 24, 2026, two critical vulnerabilities were published: CVE-2025-33248 and CVE-2026-33336. CVE-2025-33248 affects NVIDIA Megatron-LM, allowing remote code execution through a maliciously crafted file. This vulnerability can lead to code execution, privilege escalation, information disclosure, and data tampering. CVE-2026-33336 is associated with improper code generation control, but no specific affected products have been listed yet. Both vulnerabilities are currently unpatched, and no specific versions of affected products have been disclosed. The vulnerabilities are categorized under CWEs, with CVE-2025-33248 linked to CWE-502 and CVE-2026-33336 to CWE-94. Public exploits and proof-of-concept codes are being tracked for both vulnerabilities. The situation is evolving, and security professionals are advised to monitor developments closely.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Nvidia and CVE-2025-33248 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…