Adobe and Nvidia Address Dozens of Critical Vulnerabilities
Adobe and Nvidia have released security advisories patching a significant number of vulnerabilities, including critical flaws in AI products and creative software.

Adobe and Nvidia have jointly announced the release of security updates addressing a substantial number of vulnerabilities across their diverse product portfolios. The advisories, published this week, cover critical flaws in AI infrastructure, enterprise software, and creative tools, urging users to apply patches promptly to mitigate potential security risks.
Nvidia's updates include four new advisories detailing 18 vulnerabilities in its NemoClaw and OpenShell enterprise AI security products. Two of these are rated critical and could allow for code execution, privilege escalation, data tampering, information disclosure, and denial of service (DoS). Additionally, a dozen high-severity weaknesses in these products carry similar exploitation risks, with one flaw detailed by Cyera that could enable the hijacking of AI agents. Nvidia also addressed five vulnerabilities in its DGX Spark AI computer, including three high-severity flaws with potential for code execution and privilege escalation.
Further patching by Nvidia targets its Unified Fabric Manager platform, where two high- and three medium-severity issues were resolved, potentially leading to code execution and privilege escalation. The company also provided mitigation advice for Rohammer attacks against Nvidia GPUs. In separate disclosures last week, Nvidia informed customers about five vulnerabilities in Triton Inference Server, including arbitrary code execution flaws, and addressed privilege escalation and code execution vulnerabilities in Cumulus Linux and NVOS.
Adobe, which has increased its security advisory cadence to twice monthly, released seven new advisories this week. Critical code execution vulnerabilities have been patched in popular creative applications such as Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, and Adobe XD. Vulnerabilities affecting Adobe Campaign Classic were also addressed, with this advisory carrying a priority rating of 1, indicating a higher risk of exploitation.
In addition to the critical code execution flaws, Adobe has also fixed denial of service and information exposure vulnerabilities in Illustrator and its Content Credentials SDK. The company stated that none of the vulnerabilities disclosed this week have been observed being exploited in the wild, though the Campaign Classic advisory's priority rating suggests a heightened potential for attack.
The broad scope of these patches highlights the ongoing challenges faced by major technology vendors in securing complex software ecosystems, particularly as AI technologies become more integrated into enterprise and consumer products. The vulnerabilities range from direct code execution to information disclosure and denial of service, impacting a wide array of users and systems.
Users of Nvidia's AI infrastructure, enterprise platforms, and GPUs, as well as Adobe's creative suite and enterprise marketing tools, are strongly advised to review the specific advisories and apply the available updates as soon as possible. Proactive patching remains the most effective defense against the exploitation of these newly disclosed vulnerabilities.