NVIDIA disclosed two high-severity deserialization vulnerabilities affecting BioNeMo and the FLARE SDK, both tracked under CWE-502 and capable of compromising confidentiality, integrity, and availability. CVE-2026-24164 impacts BioNeMo and could allow code execution, denial of service, information disclosure, and data tampering through deserialization of untrusted data. The flaw carries a CVSS:3.1 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating remote attack potential with low complexity and high impact.
A second flaw, CVE-2026-24186, affects the NVIDIA FLARE SDK in FOBS handling, where a malicious FOBS-encoded message can trigger unsafe deserialization and lead to code execution. That issue was scored CVSS:3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, reflecting similarly severe impact with no user interaction required. NVIDIA advisory material, NVD entries, and official CVE records were published for both vulnerabilities, signaling that organizations using either platform should review vendor guidance and prioritize remediation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A deserialization vulnerability in the NVIDIA FLARE SDK's FOBS component was disclosed as CVE-2026-24186. NVIDIA indicated that a malicious FOBS-encoded message could trigger the flaw and lead to code execution, with references added to NVD, NVIDIA's advisory, and the CVE record.
A deserialization of untrusted data vulnerability in NVIDIA BioNeMo was reported and assigned CVE-2026-24164. The flaw could enable code execution, denial of service, information disclosure, and data tampering, and references were added to NVD, NVIDIA's advisory, and the CVE record.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.