NVIDIA patched two high-severity security flaws in its AI inferencing platform on September 10, 2026. These critical Triton Inference Server vulnerabilities allow unauthenticated remote attackers to trigger denial of service and access unauthorized data. Fortunately, security teams have confirmed no active exploitation or public proof-of-concept exploits for these issues.
- Product: NVIDIA Triton Inference Server
- Vulnerabilities: 2 flaws (CVE-2026-16497, CVE-2026-47625)
- Highest severity: 7.5 (High · CVSSv3)
- Worst impact: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause...
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-16497 | 7.5 | CWE-834 | Not exploited |
| CVE-2026-47625 | 7.5 | CWE-862 | Not exploited |
Why This Matters
Industry estimates show thousands of enterprise AI development pipelines rely on NVIDIA Triton to deploy production machine learning models. Therefore, exploiting these Triton Inference Server vulnerabilities exposes critical infrastructure to operational paralysis. Attackers can disrupt high-throughput model inference across cloud, edge, and data center environments. Furthermore, compromising these AI pipelines threatens data integrity and confidential business predictions.
How the Attack Works
The first flaw, CVE-2026-16497, stems from an excessive iteration weakness. According to the advisory, “NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration.” Consequently, a remote actor can send malformed inputs that exhaust server computing resources.
Meanwhile, the second vulnerability, CVE-2026-47625, involves missing authorization checks. NVIDIA warns that “A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.” Attackers exploit this gap over the network without requiring user authentication.
Affected Versions
Both vulnerabilities impact Linux installations across various release trains. Specifically, CVE-2026-16497 affects versions 0.0 through 26.06. In contrast, CVE-2026-47625 impacts versions 0.0 through 26.03.
Patch and Mitigation Steps
Administrators must update their Linux installations immediately to secure their machine learning deployments. NVIDIA resolved these flaws in recent updates. Users should obtain the fixed software from the Triton Inference Server GitHub repository. Specifically, operators should upgrade to release 26.07 or release 26.04 to prevent potential attacks.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!