CVE-2025-33244Patch

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, data tampering, and information disclosure.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 3 mentions (2026-03-24); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-03-24: 3Mentions · 2026-03-25: 2Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1Mentions · 2026-04-02: 1PoC Mentioned / Linked · 2026-03-24: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-03-24: 3Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 2Technical Details · 2026-04-02: 103-2403-2503-2603-2704-02
Signal classification2 categories
Patch
555.6%
Disclosure
444.4%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-243
Disclosure3
2026-03-252
Disclosure1Patch1
2026-03-262
Patch2
2026-03-271
Patch1
2026-04-021
Patch1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    NVIDIA patches a critical 9.0 CVSS vulnerability (CVE-2025-33244) in the Apex library. Protect your AI models from RCE—upgrade to PyTorch 2.6+ now. #NVIDIA #Apex #CyberSecurity #AISecurity #PyTorch #RCE #InfoSec #Linux #Vulnerability #MachineLearning https://securityonline.info/ai-infrastructure-at-risk-nvidia-fixes-critical-9-0-rce-flaw-in-apex-library-cve-2025-33244/ https://t.co/ZtWjuTG4ft

    Post summary

    NVIDIA released a patch for CVE-2025-33244, a critical 9.0 RCE vulnerability in the Apex library, recommending users upgrade to PyTorch 2.6+ to mitigate the issue.

    01032544
    10.9K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 NVIDIA تعالج ثغرة RCE حرجة (CVE-2025-33244) في مكتبة Apex أصدرت NVIDIA تحديثًا أمنيًا عاجلاً لمكتبة Apex لمعالجة ثغرة تنفيذ تعليمات برمجية عن بعد (RCE) حرجة، برمز CVE-2025-33244 وتصنيف خطورتها 9.0. تسمح هذه الثغرة للمهاجمين بتنفيذ تعليمات برمجية خبيثة بنظام Linux التي تستخدم المكتبة المستهدفة. يمثل هذا خطرًا مباشرًا على البنية التحتية للذكاء الاصطناعي المعرضة للخطر. يُنصح بشدة بتطبيق التحديث الأمني فورًا للتخفيف من هذا التهديد. 🔗 للمزيد: https://securityonline.info/ai-infrastructure-at-risk-nvidia-fixes-critical-9-0-rce-flaw-in-apex-library-cve-2025-33244/ #الامن_السيبراني #nvidia #cybersecurity

    Post summary

    NVIDIA released a critical patch for CVE-2025-33244 (a 9.0 severity RCE in the Apex library), urging users to apply the update immediately.

    01040257
    83 followersView on X
  • iototsecnews@iototsecnews
    Patch

    NVIDIA 製品群の複数の深刻な脆弱性が FIX:任意のコード実行/DoS 攻撃などの恐れ https://iototsecnews.jp/2026/03/26/critical-nvidia-vulnerabilities-risk-remote-code-execution-and-denial-of-service-attacks/ 今回の NVIDIA のセキュリティ更新は、AI 開発に欠かせない NVIDIA Apex などのライブラリに存在する、深刻な脆弱性を修正するものです。その中で最も深刻な脆弱性 CVE-2025-33244 は、特定のデータを読み込む際の処理の不備により、外部からの不正なプログラム操作を許してしまうものです。数多くの技術者が利用する、Triton Inference Server や NeMo Framework などのインフラ部分が影響を受けるため、迅速な対応が推奨されています。ご利用のチームは、ご注意ください。 #CVE202533215 #CVE202533216 #CVE202533238 #CVE202533242 #CVE202533244 #CVE202533247 #CVE202533248 #CVE202533254 #CVE202624141 #CVE202624150 #CVE202624151 #CVE202624152 #CVE202624157 #CVE202624158 #CVE202624159 #NVIDIA #Vulnerability

    Post summary

    The article announces NVIDIA’s security update addressing multiple critical CVEs, highlights the remote code execution risk of CVE‑2025‑33244, and urges users to apply the patch promptly.

    01000373
    481 followersView on X
  • bigmacd@bigmacd16684
    Patch

    NVIDIA patched critical CVE-2025-33244 in Apex & high-severity CVEs in Triton Inference Server, Model Optimizer, NeMo Framework & more in its AI/ML stack. #cybersecurity #patching

    Post summary

    NVIDIA released patches for several high‑severity CVEs, including CVE‑2025‑33244, across its AI/ML stack; no exploit details or active exploitation claims are mentioned.

    10000163
    5 followersView on X
  • キタきつね@foxbook
    Patch

    AIインフラストラクチャにリスク:NVIDIAがApexライブラリの重大な9.0リモートコード実行脆弱性(CVE-2025-33244)を修正 AI Infrastructure at Risk: NVIDIA Fixes Critical 9.0 RCE Flaw in Apex Library (CVE-2025-33244) #DailyCyberSecurity (Mar 25) https://securityonline.info/ai-infrastructure-at-risk-nvidia-fixes-critical-9-0-rce-flaw-in-apex-library-cve-2025-33244/

    Post summary

    NVIDIA has released a patch for its Apex library to remediate a critical remote code execution vulnerability (CVE-2025-33244), with no indication of active exploitation or PoC.

    00000367
    4.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-33244 NVIDIA APEX Linux Deserialization Vulnerability Enables Unauthorized Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-33244

    Post summary

    An NVIDIA APEX Linux deserialization bug (CVE-2025-33244) that allows unauthorized code execution has been disclosed, but no proof of concept, exploit code, active exploitation, or patch information is provided.

    00000106
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-33244 - Critical NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch ver... https://www.thehackerwire.com/vulnerability/CVE-2025-33244/ https://t.co/FLiHMcIK7A

    Post summary

    NVIDIA APEX for Linux has a critical deserialization flaw that could allow attackers to manipulate untrusted data within PyTorch environments.

    00000196
    145 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-33244: CRITICAL] Warning: NVIDIA APEX for Linux has a critical vulnerability allowing attackers to execute code, cause denial of service, and more. Update PyTorch to version 2.6+ for protection.#cve,CVE-2025-33244,#cybersecurity https://cvefind.com/CVE-2025-33244

    Post summary

    The tweet announces CVE‑2025‑33244, notes its critical nature and impact, and advises updating PyTorch to 2.6+ for protection.

    00000139
    605 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-33244: NVIDIA (CVSS: 9.0)... Pickle deserialization in NVIDIA APEX hits every PyTorch <2.6 deployment - RCE with adjacent network access and low pri... https://zerodaysignal.com/vulnerability/CVE-2025-33244 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2025‑33244 is a high‑severity (CVSS 9.0) vulnerability involving pickle deserialization in NVIDIA APEX that allows remote code execution on PyTorch deployments below 2.6. No patches, PoC code, or active exploitation details are provided in the text.

    00000231
    168 followersView on X

Explore more