NVIDIA disclosed CVE-2026-24233, a high-severity vulnerability in TensorRT-LLM for Linux caused by insecure deserialization in the product’s restricted unpickler for model weight loading. The flaw affects versions up to and including v1.3.0 rc14 and allows a local, unauthenticated attacker to trigger deserialization of untrusted data, potentially leading to remote code execution, privilege escalation, data tampering, and information disclosure. The issue carries a CVSS v3.1 score of 8.4 with vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
The vulnerability is classified as CWE-502: Deserialization of Untrusted Data, a weakness that arises when software processes attacker-controlled serialized input without sufficient validation. MITRE notes that such flaws can let attackers abuse gadget chains or unsafe object handling to alter program state, cause denial of service, or execute arbitrary code, and recommends mitigations including integrity protection for serialized data, strict allowlisting of acceptable classes, reducing available gadget types, and defensive coding patterns that block unsafe deserialization paths.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
On 2026-07-14, a CVE record was published for CVE-2026-24233, a high-severity insecure deserialization vulnerability in NVIDIA TensorRT-LLM for Linux. The flaw affects versions up to and including v1.3.0 rc14 and could allow local unauthenticated code execution, privilege escalation, data tampering, and information disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecve.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.