Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Remote Code Execution in NVIDIA TensorRT (CVE-2026-24238) via ONNX Parsing Flaw

A high‑severity (CVSS 7.8) vulnerability in NVIDIA TensorRT’s ONNX model parser allows remote code execution when a malicious ONNX file is processed. The flaw highlights the importance of continuous vulnerability management for SOC 2 audit readiness.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in NVIDIA TensorRT (CVE‑2026‑24238) via ONNX Parsing Flaw

What It Is — NVIDIA TensorRT’s ONNX model parser fails to validate array indexes in Slice operations, allowing a write‑past‑the‑end condition that can be leveraged for remote code execution. The flaw is tracked as CVE‑2026‑24238.

Exploitability — CVSS 7.8 (High). Exploitation requires user interaction (visiting a malicious page or opening a crafted file), but a successful attack runs arbitrary code in the host process. No public exploit is known yet; a vendor patch is available.

Affected Products — NVIDIA TensorRT (all versions prior to the August 2026 security update).

Why It Matters for Compliance & Audit Readiness —

  • Demonstrates the need for continuous vulnerability management to satisfy SOC 2 Security criteria (CC6.1 – System Operations).
  • Unpatched code‑execution paths constitute a control gap; mapping them to your control framework provides audit‑ready evidence.
  • Ongoing patch verification can be captured in a Trust Center dashboard to prove due diligence to customers and regulators.

Recommended Actions —

  • Deploy NVIDIA’s September 2026 patch immediately on all TensorRT instances.
  • Update your asset inventory to tag TensorRT versions and enable automated compliance scanning.
  • Map the vulnerability to SOC 2 CC6.1 and record remediation evidence in your continuous‑compliance platform.
  • Incorporate runtime integrity checks for ONNX model parsing into your secure‑development lifecycle.

Source: Zero Day Initiative Advisory ZDI‑26‑592

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-592/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →