News report
NVIDIA GPU Driver Security Update Fixes 114 Vulnerabilities
NVIDIA's September 2026 GPU driver and vGPU security update addresses 114 CVEs, including high-severity local privilege-escalation paths.
On this page
NVIDIA's September security release covers a large driver surface
NVIDIA disclosed a broad September 2026 security update for its GPU display drivers and vGPU software on September 30. The published vulnerability set contains 114 CVEs across Windows, Linux and virtual-GPU components, making this a security-focused driver update rather than a normal game-optimization release.
For ordinary GeForce users, the practical action is branch-specific: NVIDIA's affected-version data lists Windows fixes at 616.56 for R615, 610.60 for R610 and 582.78 for the R580 legacy path used by Maxwell, Pascal and Volta GPUs. Users should match the installed branch and supported GPU rather than assuming one version number applies to every card.
| CVE | Affected path | Severity / practical boundary |
|---|---|---|
| CVE-2026-47505 | Windows kernel-mode display driver use-after-free | CVSS 7.8 High; local, low-privilege access |
| CVE-2026-47500 | Windows and Linux kernel-mode reference-count cleanup | CVSS 7.8 High; local, low-privilege access |
| CVE-2026-47489 | Linux kernel-mode memory-permission handling | CVSS 7.8 High; local attack vector |
| CVE-2026-47574 | Linux vGPU Virtual GPU Manager | Enterprise virtualization path; separate from a normal desktop GeForce install |
The highest desktop-driver issues require local execution
Several of the highest-severity display-driver flaws are scored CVSS 7.8 and use a local attack vector with low privileges and no user interaction. Examples include CVE-2026-47505 on Windows and CVE-2026-47500 across Windows and Linux, both involving use-after-free conditions in kernel-mode driver code.
That boundary matters. These entries are serious because successful exploitation can include code execution or privilege escalation, but the published vectors do not describe a drive-by network attack against an otherwise unreachable PC. An attacker generally needs a way to execute code locally first.
GeForce users should update the branch their GPU actually supports
Current GeForce Windows systems on R615 should be on 616.56 or later for the affected September set. NVIDIA also lists 610.60 for the GeForce R610 branch. For Maxwell, Pascal and Volta products on the R580 security-maintenance branch, the fixed Windows version is 582.78.
Linux fixed versions differ by branch and should be taken from NVIDIA's advisory for the installed driver family. Enterprise RTX, Quadro, NVS, Tesla and vGPU deployments also have their own version matrix, so administrators should not substitute the consumer GeForce number for those products.
No evidence here establishes active exploitation
The public CVE records and NVIDIA advisory establish affected software, severity and fixed versions. They do not by themselves establish that these flaws are being exploited in the wild, and Core Tech Tips found no authoritative active-exploitation notice for the highlighted desktop-driver CVEs during this review.
The sensible response is therefore straightforward patching rather than panic: update through NVIDIA's normal driver channel, verify the installed version, and apply the branch-specific enterprise or Linux update where applicable.
Sources
Primary and technical sources
These sources support the reporting and analysis above. Current stories are updated when later evidence materially changes the facts.
01 NVIDIA
NVIDIA Product Security — September 2026 GPU driver advisory data02 CVE Program
CVE-2026-47505 record03 CVE Program
CVE-2026-47500 record
Related
Continue from here
Useful next steps selected from the same technical reference and publication system.
Compatibility & upgrades
NVIDIA Smooth Motion vs DLSS Frame Generation Explained
Understand NVIDIA Smooth Motion versus DLSS Frame Generation: driver-level interpolation, game integration, supported APIs and GPUs, latency, and when each applies.
Technical guide
How to Back Up Installed Drivers in Windows 11
Export third-party driver packages from the Windows 11 driver store with PnPUtil, preserve them before a reinstall, and understand what the backup does and does not contain.
Technical guide
How to Roll Back a Device Driver in Windows 11: Device Manager, Previous Packages, Recovery, and Verification
Safely roll back a problematic Windows 11 device driver, handle an unavailable rollback button, use supported previous packages, and verify the result.
Compatibility & upgrades
How to Check a Driver’s Digital Signature in Windows 11
Check whether a Windows 11 driver package or driver file is digitally signed, understand catalog versus embedded signatures, and interpret what a valid signature actually proves.