NVIDIA has issued an important security bulletin for February 2026, warning network administrators of three high-severity vulnerabilities impacting its Cumulus Linux and NVOS platforms. If left unpatched, these flaws could allow attackers to gain unauthorized administrative control over critical network infrastructure.
All three vulnerabilities—tracked as CVE-2025-33179, CVE-2025-33180, and CVE-2025-33181—reside within the NVIDIA User Experience (NVUE) interface. According to the bulletin, “A successful exploit of this vulnerability might lead to escalation of privileges.”
Here is the breakdown of the specific threats:
- CVE-2025-33179 (CVSS Score: 8.0): This flaw (CWE-266) creates a scenario “where a low-privileged user could run an unauthorized command.”
- CVE-2025-33180 (CVSS Score: 8.0): This vulnerability (CWE-77) is an injection flaw “where a low-privileged user could inject a command.”
- CVE-2025-33181 (CVSS Score: 7.3): Similar to the previous flaw, this is also a command injection vulnerability (CWE-77) “where a low-privileged user could inject a command.”
NVIDIA has rolled out security updates across its General Availability (GA) and Long-Term Support (LTS) branches for Cumulus Linux, as well as several versions of NVOS. Administrators are strongly advised to apply the updated versions immediately to secure their environments.
| CVE IDs Addressed | Affected Products | Platform or OS | Affected Versions | Updated Version |
|---|---|---|---|---|
|
CVE-2025-33179 |
Cumulus Linux GA | Cumulus Linux | All versions prior to 5.14 (5.13.x, 5.12.x, and older GA versions) | 5.14 |
| Cumulus Linux LTS | All versions prior to 5.11.4 | 5.11.4 | ||
| All versions prior to 5.9.4 | 5.9.4 | |||
| NVOS | GB200 | All versions prior to 25.02.2452 | 25.02.2452 | |
| GB300 (1.0) | All versions prior to 25.02.4282 | 25.02.4282 | ||
| IBSwitch XDR | All versions prior to 25.02.5030 | 25.02.5030 |
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.