NVIDIA published Security Bulletin 5872 covering 19 CVEs in its NemoClaw and OpenShell products, including identifiers from CVE-2026-65081 through CVE-2026-65093, CVE-2026-65096 through CVE-2026-65099, and CVE-2026-65105. The published bulletin repository provides CSAF and Markdown versions of the advisory, although the available directory listing does not disclose technical details, remediation guidance, or exploitation status for all listed flaws.
Two disclosed high-severity issues are CVE-2026-65091, an OS command-injection flaw affecting NVIDIA OpenShell through version 0.0.33 on all platforms, and CVE-2026-65105, a missing-authentication flaw in the NemoClaw Linux inference-server setup affecting versions 0 through 0.0.25. A malicious gateway could exploit the OpenShell issue over the network with user interaction to execute commands, tamper with data, or disclose information (CVSS 8.8), while an unauthenticated remote attacker could access an affected NemoClaw inference service and cause information disclosure or denial of service (CVSS 8.1).

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-849, identifying vulnerabilities affecting NVIDIA Unified Fabric Manager and NVIDIA DGX Spark versions earlier than 1.110.13, in addition to NemoClaw and OpenShell. It advised administrators to review NVIDIA's August 2026 bulletins and apply required updates when available.
CVE-2026-65105 was published as a high-severity missing-authentication flaw in the NVIDIA NemoClaw inference-server setup for Linux, affecting versions through 0.0.25. Remote unauthenticated attackers could access the inference service, potentially causing information disclosure or denial of service.
CVE-2026-65091 was published as a high-severity OS command-injection vulnerability affecting NVIDIA OpenShell versions through 0.0.33. A malicious gateway could exploit the issue to enable code execution, data tampering, or information disclosure.
NVIDIA published Security Bulletin 5872, “NVIDIA NemoClaw and OpenShell - August 2026,” listing 19 associated CVEs, including CVE-2026-65091 and CVE-2026-65105.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecve.org
Open sourcecve.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.