Adobe and Nvidia on Tuesday announced patches for dozens of vulnerabilities affecting their products, including flaws rated critical severity.
Nvidia
Nvidia published four new advisories on Tuesday. One advisory alerts customers to 18 security vulnerabilities in NemoClaw and OpenShell, enterprise AI security and runtime infrastructure products designed to wrap around autonomous AI agents.
Two of the vulnerabilities are critical and they can be exploited for code execution, privilege escalation, data tampering, information disclosure, and denial of service (DoS).
A dozen of the other weaknesses have a high severity rating and their exploitation can have a similar impact. Cyera has detailed one of these vulnerabilities, showing how it can be exploited to hijack AI agents.
Five vulnerabilities have been resolved by Nvidia in its DGX Spark AI computer, including three high-severity flaws that can be exploited for code execution, privilege escalation, data tampering, and DoS.
In the Unified Fabric Manager platform, the tech giant fixed two high- and three medium-severity issues that, if exploited, could lead to code execution and privilege escalation.
The fourth advisory addresses Rohammer attacks against Nvidia GPUs, with the vendor providing additional mitigation advice.
In addition to the advisories published this week, Nvidia informed customers last week about five vulnerabilities in Triton Inference Server, including flaws that can allow arbitrary code execution. The company informed customers the same day about privilege escalation and code execution vulnerabilities patched in Cumulus Linux and NVOS.
Adobe
Adobe is now publishing security advisories twice a month and on Tuesday it released seven new advisories addressing dozens of vulnerabilities.
The company has patched critical code execution vulnerabilities in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD, and Campaign Classic.
DoS and information exposure flaws have been fixed in Illustrator and Content Credentials SDK.
Adobe says none of the vulnerabilities have been exploited in the wild, and only the Campaign Classic advisory has a priority rating of 1, indicating it’s at higher risk of exploitation.
Related: Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities
Related: Adobe Commerce Bug Targeted Immediately After Disclosure
Related: Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
Related: Nvidia and Tech Giants Launch AI Security Alliance

