NVIDIA Patches Critical NemoClaw, OpenShell Flaws
NVIDIA’s NemoClaw platform is designed to help developers build autonomous AI agents, while OpenShell provides a secured runtime intended to isolate their actions. Such safeguards are increasingly important as agents gain the ability to invoke tools, execute code and interact with sensitive data without constant human supervision. A failure in the sandbox layer could therefore expose systems beyond an individual AI workload and undermine a central security control for agentic applications.
NVIDIA has released updates addressing 18 vulnerabilities across NemoClaw and OpenShell. Two were rated critical, with CVSS scores of 9.9, and the affected flaws include a sandbox-escape issue that could enable code execution or data tampering. The company urged customers to obtain the latest software through the projects’ GitHub repositories and apply the fixes promptly to reduce their exposure to potential attacks.
All Coverage
1 original reportsThe Backstory
The history behind this eventNVIDIA Issues March 2026 Security Bulletin, Patches High-Risk Flaws in AI Frameworks
NVIDIA's GPU drivers and software packages including Triton Inference Server, NeMo Framework, Model Optimizer and Apex are widely used for AI model training and inference. If exploited, the vulnerabilities could compromise server data, service availability and system privileges, making timely patching particularly important for enterprise deployments.
NVIDIA issued a security bulletin in March 2026 addressing high-risk vulnerabilities in its hardware drivers and several AI software packages. The most severe flaws affect the Apex PyTorch extension and could enable remote code execution or privilege escalation. Triton vulnerabilities could also cause denial of service, data leaks or arbitrary code execution, and NVIDIA recommends upgrading promptly.
Nvidia Patches High-Risk Security Flaw in NemoClaw AI Agent Platform
NemoClaw is Nvidia’s platform for developing autonomous AI agents, enabling businesses to build applications that can perform tasks independently. Because these agents may access internal data, credentials and system tools, exploited platform vulnerabilities could heighten the risks of sensitive information leaks and breaches of corporate systems.
Nvidia released a software update in 2026 to patch two NemoClaw security vulnerabilities. One of them, CVE-2026-24222, was rated high risk and could lead to information disclosure. The company urged users to upgrade to version 0.0.18 as soon as possible to reduce the risk of attackers exploiting the flaws.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →