Adobe and Nvidia patch dozens of vulnerabilities across a wide range of products, from enterprise AI infrastructure to creative and design tools. Both vendors published new advisories, including multiple issues rated critical, as well as high- and medium-severity flaws that could affect availability, confidentiality, and system integrity.
Below is a clear overview of what was fixed, which platforms were impacted, and why these updates matter for teams running AI workloads or using Adobe software in production environments.
Nvidia releases multiple advisories for AI and infrastructure
Nvidia published four new security advisories, each targeting different components in its enterprise ecosystem. The scope includes products used to secure and operate autonomous AI agent workflows, AI compute systems, and GPU-related defenses.
Critical issues in NemoClaw and OpenShell
One advisory covers 18 security vulnerabilities in NemoClaw and OpenShell, which Nvidia describes as enterprise AI security and runtime infrastructure products designed to wrap around autonomous AI agents.
Two of the addressed vulnerabilities are rated critical. According to Nvidia, they can be exploited to achieve outcomes such as code execution, privilege escalation, data tampering, information disclosure, and denial of service (DoS). The remaining vulnerabilities in the same advisory carry high severity and can lead to similar impact if attackers can successfully exploit them.
Third-party research highlighted in the coverage also points to exploitation paths that could enable attackers to hijack AI agents, showing how runtime security weaknesses may translate into real-world compromise of automated systems.
Fixes for DGX Spark AI compute
Another advisory focuses on the DGX Spark AI computer. Nvidia states that it resolved five vulnerabilities, including three high-severity issues. These problems, if misused, could allow attackers to perform code execution, privilege escalation, data tampering, or trigger DoS conditions.
Unified Fabric Manager: code execution and privilege escalation
Nvidia also updated Unified Fabric Manager with two high-severity and three medium-severity fixes. The potential consequences described include code execution and privilege escalation when vulnerabilities are exploited.
Rohammer GPU protections and mitigation guidance
The fourth advisory addresses Rohammer attacks targeting Nvidia GPUs. In addition to the security communication, Nvidia provides further mitigation advice, which is important because some GPU-related attack classes require configuration and operational changes beyond a simple patch.
Nvidia also addressed issues earlier in the month
Beyond the advisories released this week, Nvidia previously informed customers about additional vulnerabilities in other platforms. This includes updates to the Triton Inference Server, where five vulnerabilities were described as capable of allowing arbitrary code execution.
Separately, Nvidia also communicated on the same day about privilege escalation and code execution vulnerabilities patched in Cumulus Linux and NVOS. Taken together, the announcements indicate sustained focus on both AI runtime components and the operating layers used to run and manage those systems.
Adobe releases new advisories twice a month
Alongside Nvidia’s updates, Adobe shared that it is now publishing security advisories twice a month. On Tuesday, Adobe released seven new advisories covering dozens of vulnerabilities across its products.
Critical code execution fixes in creative tools
Adobe’s most urgent patches address critical code execution vulnerabilities in multiple products. The affected applications include Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD, and Campaign Classic.
For organizations that rely on these tools for day-to-day creative work, critical code execution issues can raise the risk of malware installation or broader compromise if attackers can deliver crafted inputs or use other delivery mechanisms that trigger the vulnerability.
DoS and information exposure patches
Adobe also reported fixes for denial of service and information exposure issues in Illustrator and its Content Credentials SDK. While these are not necessarily the same as code execution problems, availability impacts can still disrupt production workflows, and information exposure can create confidentiality concerns depending on the data handled by the environment.
Is there evidence of exploitation in the wild?
Adobe states that none of the vulnerabilities have been exploited in the wild. That reduces immediate pressure for active exploitation, but it does not remove the need for patching—attackers often shift quickly once updates are available publicly, especially when critical flaws are involved.
Adobe also lists Campaign Classic with a priority rating of 1, which the advisory describes as higher risk of exploitation. Teams using Campaign Classic should treat this component as a priority area for remediation.
What teams should do next
When vendors announce that Adobe and Nvidia patch multiple vulnerabilities at once—especially those rated critical—security teams typically need to move quickly and methodically. Consider the following actions to reduce exposure:
- Inventory exposure: identify which versions of Nvidia enterprise products and which Adobe applications are in use.
- Prioritize critical items: focus first on critical code execution vulnerabilities and systems labeled with higher risk priority.
- Apply GPU mitigations when required: for GPU-focused classes such as Rohammer, ensure both patching and any additional mitigation guidance are followed.
- Validate in a controlled environment: test updates when possible to minimize disruption to creative pipelines and AI workloads.
- Monitor after deployment: watch for unusual behavior, crashes, or unexpected access patterns that could indicate attempted exploitation.
Why these updates matter
These advisories highlight two key realities for modern organizations. First, AI infrastructure is increasingly part of enterprise attack surfaces, especially when runtime components interact with autonomous agent workflows. Second, creative and design software remains a high-value target because it can be widely used across organizations and may process content from external sources.
By publishing updates across both categories, Nvidia and Adobe provide concrete opportunities to reduce risk—provided organizations act on the releases and align remediation with the severity and priority of each issue.
Conclusion
Adobe and Nvidia patch dozens of vulnerabilities spanning AI security tooling, GPU environments, AI compute systems, and popular creative applications. With critical code execution flaws and other high-impact issues addressed across multiple platforms, administrators and security teams should review their software inventories, prioritize the most urgent fixes (including higher-risk advisories), and implement the recommended mitigations as soon as feasible.
Source: https://www.securityweek.com/adobe-and-nvidia-patch-dozens-of-vulnerabilities/
