Skip to content
Multiple CVEs Discovered in NVIDIA Megatron and Other Products

Multiple CVEs Discovered in NVIDIA Megatron and Other Products

First seen 24 Mar 2026, 21:48 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 25, 2026 at 20:47 UTC

On March 24, 2026, two critical vulnerabilities were published: CVE-2025-33248 and CVE-2026-33336. CVE-2025-33248 affects NVIDIA Megatron-LM, allowing remote code execution through a maliciously crafted file. This vulnerability can lead to code execution, privilege escalation, information disclosure, and data tampering. CVE-2026-33336 is associated with improper code generation control, but no specific affected products have been listed yet. Both vulnerabilities are currently unpatched, and no specific versions of affected products have been disclosed. The vulnerabilities are categorized under CWEs, with CVE-2025-33248 linked to CWE-502 and CVE-2026-33336 to CWE-94. Public exploits and proof-of-concept codes are being tracked for both vulnerabilities. The situation is evolving, and security professionals are advised to monitor developments closely.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 196d ago How this analysis works

Timeline

2026-03-24
CVE-2025-33248 published
2026-03-24
CVE-2026-33336 published

More articles in this cluster (3)

Following this threat?

Track Nvidia and CVE-2025-33248 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed