Adobe and Nvidia patch dozens of critical security flaws
Adobe and Nvidia issued patches Tuesday for dozens of vulnerabilities, including two critical flaws in Nvidia’s NemoClaw/OpenShell and critical code-execution bugs in Adobe’s Substance 3D apps.
Adobe and Nvidia released security updates Tuesday that fix dozens of vulnerabilities across AI, GPU and creative software products. Nvidia published four advisories covering runtime and infrastructure components for AI agents, GPU reliability, and system software. Adobe issued seven advisories and said it will publish security bulletins twice a month going forward.
Nvidia flagged 18 vulnerabilities in NemoClaw and OpenShell, its enterprise AI security and runtime infrastructure used to wrap autonomous AI agents. Two of those flaws were rated critical and can be used for arbitrary code execution, privilege escalation, data tampering, information disclosure and denial-of-service. Nvidia classified about a dozen additional issues in the same set as high severity with similar potential impacts. Security firm Cyera published technical details on one defect and demonstrated how it could be used to hijack AI agents.
Separately, Nvidia resolved five vulnerabilities in its DGX Spark AI system, three of which were rated high severity and could lead to code execution, privilege escalation, data tampering and service disruption. The company also fixed two high- and three medium-severity flaws in Unified Fabric Manager that could permit code execution or privilege escalation. A fourth advisory provided guidance and mitigations for Rohammer attacks that can affect NVIDIA GPU reliability and security. Nvidia additionally notified customers last week about five flaws in Triton Inference Server that can allow arbitrary code execution and disclosed fixes for privilege escalation and code execution bugs in Cumulus Linux and NVOS.
Adobe’s seven advisories cover a range of creative and enterprise products. The updates fix critical code-execution vulnerabilities in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, Adobe XD and Campaign Classic. Adobe also patched denial-of-service and information-exposure issues in Illustrator and the Content Credentials SDK. Adobe reported that none of the newly fixed vulnerabilities have been observed exploited in the wild and assigned a priority rating of 1 to the Campaign Classic advisory, indicating a higher risk of exploitation relative to the other fixes.
Both vendors urged customers to apply the available updates promptly. Nvidia’s advisories include recommended mitigations and configuration changes for affected deployments, and Adobe’s bulletins list affected product versions and remediation paths. System administrators and security teams operating AI infrastructure, Nvidia GPU-based systems or Adobe creative and campaign tools should review the vendor advisories and update to the fixed versions.
The disclosures arrive amid growing enterprise use of AI agents and GPU-accelerated systems, increasing focus on vulnerabilities in runtime tooling and inference platforms.








