Back to Feed
VulnerabilitiesAug 26, 2026

Adobe and Nvidia Patch Dozens of Vulnerabilities

Adobe and Nvidia release patches for dozens of critical and high-severity vulnerabilities.

Summary

Adobe and Nvidia have jointly released advisories detailing patches for numerous vulnerabilities across their product lines. Nvidia addressed critical flaws in its AI infrastructure products like NemoClaw and OpenShell, as well as issues in DGX Spark and Unified Fabric Manager. Adobe patched critical code execution vulnerabilities in several Substance 3D applications, XD, and Campaign Classic. While most vulnerabilities are not reported as exploited in the wild, the disclosures highlight ongoing security efforts for AI and creative software.

Full text

Adobe and Nvidia on Tuesday announced patches for dozens of vulnerabilities affecting their products, including flaws rated critical severity. Nvidia Nvidia published four new advisories on Tuesday. One advisory alerts customers to 18 security vulnerabilities in NemoClaw and OpenShell, enterprise AI security and runtime infrastructure products designed to wrap around autonomous AI agents. Two of the vulnerabilities are critical and they can be exploited for code execution, privilege escalation, data tampering, information disclosure, and denial of service (DoS). A dozen of the other weaknesses have a high severity rating and their exploitation can have a similar impact. Cyera has detailed one of these vulnerabilities, showing how it can be exploited to hijack AI agents. Five vulnerabilities have been resolved by Nvidia in its DGX Spark AI computer, including three high-severity flaws that can be exploited for code execution, privilege escalation, data tampering, and DoS. In the Unified Fabric Manager platform, the tech giant fixed two high- and three medium-severity issues that, if exploited, could lead to code execution and privilege escalation. Advertisement. Scroll to continue reading. The fourth advisory addresses Rohammer attacks against Nvidia GPUs, with the vendor providing additional mitigation advice. In addition to the advisories published this week, Nvidia informed customers last week about five vulnerabilities in Triton Inference Server, including flaws that can allow arbitrary code execution. The company informed customers the same day about privilege escalation and code execution vulnerabilities patched in Cumulus Linux and NVOS. Adobe Adobe is now publishing security advisories twice a month and on Tuesday it released seven new advisories addressing dozens of vulnerabilities. The company has patched critical code execution vulnerabilities in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD, and Campaign Classic. DoS and information exposure flaws have been fixed in Illustrator and Content Credentials SDK. Adobe says none of the vulnerabilities have been exploited in the wild, and only the Campaign Classic advisory has a priority rating of 1, indicating it’s at higher risk of exploitation. Related: Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities Related: Adobe Commerce Bug Targeted Immediately After Disclosure Related: Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft Related: Nvidia and Tech Giants Launch AI Security Alliance Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security UpdateFirst Malware Built Specifically for Car Head Units Fuels BotnetCISA Warns of Exploited Oracle WebLogic VulnerabilityReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited91 Vulnerabilities Patched in Spring Application FrameworkVenezuelan Gets Record Federal Prison Term for ATM JackpottingPersonal Information Exposed in Apollo Global Data BreachAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund Latest News CISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksThe MFA Identity Trap: When Authentication Creates a False Sense of SecurityChrome 152 Patches Over 300 VulnerabilitiesSensitive Information Exposed in Nutex Health Data BreachCISA Warns of Exploited Gitea VulnerabilityLinux Foundation to Govern TRACE, an Open Standard for AI Runtime AttestationAlice Raises $140M to Expand AI Model Defenses and Enterprise GuardrailsWordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTrellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.Mike Marshall has been appointed State Chief Information Security Officer at the California Department of Technology.Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.More People On The MoveExpert Insights The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email

Entities

Adobe (vendor)Nvidia (vendor)NemoClaw (product)OpenShell (product)DGX Spark (product)Unified Fabric Manager (product)