CVE-2026-24262 is a vulnerability discovered in the system firmware of NVIDIA DGX Spark. A privileged attacker can exploit an out-of-bounds write flaw in the firmware. Successful exploitation may result in arbitrary code execution, privilege escalation, denial of service, information disclosure, and data tampering. The vulnerability requires privileged access to exploit, somewhat limiting the attack surface. NVIDIA has published a security advisory through their product-security GitHub repository. The vulnerability is tracked by both NVD and CVE.org. Given the range of potential impacts including code execution and privilege escalation, this is considered a high-severity issue. The DGX Spark is an AI computing platform, making this vulnerability particularly relevant to high-performance AI infrastructure environments.