Security NEXT•August 6, 2026•🇯🇵Translated from Japanese

Critical Vulnerabilities Disclosed in NVIDIA Dynamo with Remote Attack Risks

NVIDIA has disclosed multiple vulnerabilities in its NVIDIA Dynamo software, a Linux-based solution designed for serving multimodal data. The issues were detailed in a security advisory published on August 4, 2026, affecting various versions with a combined total of 15 CVEs confirmed.

The most critical finding is CVE-2026-24254, an out-of-bounds write vulnerability in the multimodal serving topology. This flaw permits remote attackers to exploit it without authentication, earning a CVSS v3.1 base score of 9.8 and a Critical severity rating. A noted discrepancy exists between the score and the vector string, which may require future correction.

Two additional vulnerabilities follow with CVSS scores of 8.2. CVE-2026-24253 involves out-of-bounds memory writes that could lead to denial of service. CVE-2026-47623 arises from deserializing untrusted data, potentially enabling denial of service or data tampering.

Updated versions addressing these issues are now available from NVIDIA. Organizations using NVIDIA Dynamo should apply the patches promptly to reduce exposure to these remote attack vectors.

Related articles

BoletimSec•Vulnerabilities & Exploits

Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes

Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.

Security NEXT•Vulnerabilities & Exploits

Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution

GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.

Security NEXT•Vulnerabilities & Exploits

WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM

WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.

Security NEXT•Vulnerabilities & Exploits

Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings

Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.