Adobe and Nvidia on Tuesday announced patches for dozens of vulnerabilities affecting their products, including critical-severity bugs.
Nvidia
Nvidia released four new advisories on Tuesday. An advisory alerts customers to 18 vulnerabilities in NemoClaw and OpenShell, the enterprise AI security and runtime infrastructure products designed to bypass autonomous AI agents.
Two of the vulnerabilities are critical and can be exploited for code execution, privilege escalation, data manipulation, information disclosure and denial of service (DoS).
A dozen of the other vulnerabilities are of high severity and their exploitation could have similar effects. Cyera has detailed One of these vulnerabilities shows how it can be exploited to hijack AI agents.
Five vulnerabilities have been fixed by Nvidia in its AI computer DGX Spark, including three high-severity vulnerabilities that can be exploited for code execution, privilege escalation, data manipulation and DoS.
In the Unified Fabric Manager platform, the tech giant has fixed two high-severity and three medium-severity issues that could lead to code execution and privilege escalation if exploited.
The fourth recommendation addresses Rohammer attacks against Nvidia GPUs, with the vendor providing additional advice on mitigation.
In addition to the notices released this week, Nvidia informed customers last week of five vulnerabilities in the Triton Inference Server, including vulnerabilities that could allow arbitrary code execution. The company notified customers on the same day of the privilege escalation and code execution vulnerabilities patched in Cumulus Linux and NVOS.
Adobe
Adobe now publishes security advisories twice a month and on Tuesday released seven new advisories that address dozens of vulnerabilities.
The company has fixed critical code execution vulnerabilities in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD and Campaign Classic.
DoS and information disclosure bugs have been fixed in Illustrator and Content Credentials SDK.
Adobe says none of the vulnerabilities have yet been exploited and only the Campaign Classic advisory has a priority rating of 1, indicating it is at higher risk of exploitation.
Related: Adobe fixes critical vulnerabilities in ColdFusion and Campaign Classic
Related: Adobe Commerce bug fixed immediately after disclosure
Related: Bug in Adobe extension with 300 million installs allows WhatsApp data theft
Related: Nvidia and Tech Giants launch AI Security Alliance
