News report

NVIDIA GPU Driver Security Update Fixes 114 Vulnerabilities

NVIDIA's September 2026 GPU driver and vGPU security update addresses 114 CVEs, including high-severity local privilege-escalation paths.

On this page
  1. NVIDIA's September security release covers a large driver surface
  2. The highest desktop-driver issues require local execution
  3. GeForce users should update the branch their GPU actually supports
  4. No evidence here establishes active exploitation

NVIDIA's September security release covers a large driver surface

NVIDIA disclosed a broad September 2026 security update for its GPU display drivers and vGPU software on September 30. The published vulnerability set contains 114 CVEs across Windows, Linux and virtual-GPU components, making this a security-focused driver update rather than a normal game-optimization release.

For ordinary GeForce users, the practical action is branch-specific: NVIDIA's affected-version data lists Windows fixes at 616.56 for R615, 610.60 for R610 and 582.78 for the R580 legacy path used by Maxwell, Pascal and Volta GPUs. Users should match the installed branch and supported GPU rather than assuming one version number applies to every card.

Selected September 2026 NVIDIA GPU-driver vulnerabilities
CVEAffected pathSeverity / practical boundary
CVE-2026-47505Windows kernel-mode display driver use-after-freeCVSS 7.8 High; local, low-privilege access
CVE-2026-47500Windows and Linux kernel-mode reference-count cleanupCVSS 7.8 High; local, low-privilege access
CVE-2026-47489Linux kernel-mode memory-permission handlingCVSS 7.8 High; local attack vector
CVE-2026-47574Linux vGPU Virtual GPU ManagerEnterprise virtualization path; separate from a normal desktop GeForce install

The highest desktop-driver issues require local execution

Several of the highest-severity display-driver flaws are scored CVSS 7.8 and use a local attack vector with low privileges and no user interaction. Examples include CVE-2026-47505 on Windows and CVE-2026-47500 across Windows and Linux, both involving use-after-free conditions in kernel-mode driver code.

That boundary matters. These entries are serious because successful exploitation can include code execution or privilege escalation, but the published vectors do not describe a drive-by network attack against an otherwise unreachable PC. An attacker generally needs a way to execute code locally first.

GeForce users should update the branch their GPU actually supports

Current GeForce Windows systems on R615 should be on 616.56 or later for the affected September set. NVIDIA also lists 610.60 for the GeForce R610 branch. For Maxwell, Pascal and Volta products on the R580 security-maintenance branch, the fixed Windows version is 582.78.

Linux fixed versions differ by branch and should be taken from NVIDIA's advisory for the installed driver family. Enterprise RTX, Quadro, NVS, Tesla and vGPU deployments also have their own version matrix, so administrators should not substitute the consumer GeForce number for those products.

No evidence here establishes active exploitation

The public CVE records and NVIDIA advisory establish affected software, severity and fixed versions. They do not by themselves establish that these flaws are being exploited in the wild, and Core Tech Tips found no authoritative active-exploitation notice for the highlighted desktop-driver CVEs during this review.

The sensible response is therefore straightforward patching rather than panic: update through NVIDIA's normal driver channel, verify the installed version, and apply the branch-specific enterprise or Linux update where applicable.

Sources

Primary and technical sources

These sources support the reporting and analysis above. Current stories are updated when later evidence materially changes the facts.

  1. 01 NVIDIA

    NVIDIA Product Security — September 2026 GPU driver advisory data
  2. 02 CVE Program

    CVE-2026-47505 record
  3. 03 CVE Program

    CVE-2026-47500 record

Related

Technical guide

How to Back Up Installed Drivers in Windows 11

Export third-party driver packages from the Windows 11 driver store with PnPUtil, preserve them before a reinstall, and understand what the backup does and does not contain.