Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Adobe and Nvidia Patch Dozens of Vulnerabilities

Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.

Ivanti Fortinet Splunk Atlassian Nvidia Adobe vulnerability patches

Adobe and Nvidia on Tuesday announced patches for dozens of vulnerabilities affecting their products, including flaws rated critical severity. 

Nvidia

Nvidia published four new advisories on Tuesday. One advisory alerts customers to 18 security vulnerabilities in NemoClaw and OpenShell, enterprise AI security and runtime infrastructure products designed to wrap around autonomous AI agents.

Two of the vulnerabilities are critical and they can be exploited for code execution, privilege escalation, data tampering, information disclosure, and denial of service (DoS). 

A dozen of the other weaknesses have a high severity rating and their exploitation can have a similar impact. Cyera has detailed one of these vulnerabilities, showing how it can be exploited to hijack AI agents.

Five vulnerabilities have been resolved by Nvidia in its DGX Spark AI computer, including three high-severity flaws that can be exploited for code execution, privilege escalation, data tampering, and DoS.

In the Unified Fabric Manager platform, the tech giant fixed two high- and three medium-severity issues that, if exploited, could lead to code execution and privilege escalation. 

Advertisement. Scroll to continue reading.

The fourth advisory addresses Rohammer attacks against Nvidia GPUs, with the vendor providing additional mitigation advice.

In addition to the advisories published this week, Nvidia informed customers last week about five vulnerabilities in Triton Inference Server, including flaws that can allow arbitrary code execution. The company informed customers the same day about privilege escalation and code execution vulnerabilities patched in Cumulus Linux and NVOS.

Adobe

Adobe is now publishing security advisories twice a month and on Tuesday it released seven new advisories addressing dozens of vulnerabilities.

The company has patched critical code execution vulnerabilities in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD, and Campaign Classic. 

DoS and information exposure flaws have been fixed in Illustrator and Content Credentials SDK.

Adobe says none of the vulnerabilities have been exploited in the wild, and only the Campaign Classic advisory has a priority rating of 1, indicating it’s at higher risk of exploitation.

Related: Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities

Related: Adobe Commerce Bug Targeted Immediately After Disclosure

Related: Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

Related: Nvidia and Tech Giants Launch AI Security Alliance

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

Trellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.