CVE-2026-24239: High severity Nvidia NeMo Speech vulnerability
Published Sep 22, 2026
·Updated
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Affected Software
1 affected component
Nvidia NeMo Speech
Event History
Sep 22, 2026
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which environments should be considered exposed?
NVIDIA NeMo Speech is affected on all platforms. Exposure exists where the product processes malicious data created by an attacker.
2
What does exploitation require?
The attack requires malicious attacker-created data and user interaction. The CVSS vector indicates no attacker privileges are required, while attack complexity is low.
3
What could an attacker achieve after successful exploitation?
Successful exploitation could result in code execution, information disclosure, and data tampering. The reported impacts include high confidentiality, integrity, and availability effects.