Adobe and Nvidia Patch Dozens of Vulnerabilities

Two Tech Giants, Adobe and Nvidia, Rush to Patch Dozens of Vulnerabilities in Their Products

In a bid to safeguard their customers’ sensitive data, Adobe and Nvidia have simultaneously released patches for dozens of vulnerabilities affecting their products. The patches address critical code execution flaws, as well as high-severity weaknesses that could lead to denial-of-service (DoS) attacks, privilege escalation, and information disclosure.

Adobe has been particularly proactive in addressing the issue, publishing seven new security advisories this week alone. Among the vulnerabilities patched by Adobe are critical code execution flaws in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD, and Campaign Classic. Additionally, DoS and information exposure flaws have been fixed in Illustrator and Content Credentials SDK.

Nvidia, on the other hand, has published four new advisories detailing vulnerabilities in its enterprise AI security and runtime infrastructure products, NemoClaw and OpenShell. Two of these vulnerabilities are critical and can be exploited for code execution, privilege escalation, data tampering, information disclosure, and DoS. A dozen other weaknesses have a high severity rating, with one particularly concerning vulnerability that could allow AI agents to be hijacked.

The patches also address five vulnerabilities in Nvidia’s DGX Spark AI computer, including three high-severity flaws that can lead to code execution, privilege escalation, data tampering, and DoS. Furthermore, two high- and three medium-severity issues have been resolved in the Unified Fabric Manager platform, which could result in code execution and privilege escalation if exploited.

In a concerning trend, it appears that Nvidia has only recently informed customers about some of these vulnerabilities. In addition to the advisories published this week, Nvidia also disclosed five vulnerabilities in Triton Inference Server last week, including flaws that allow arbitrary code execution. Furthermore, the company alerted customers to privilege escalation and code execution vulnerabilities patched in Cumulus Linux and NVOS.

While Adobe has assured users that none of the vulnerabilities have been exploited in the wild, the sheer number of vulnerabilities addressed in this patch cycle underscores the importance of staying vigilant and keeping software up-to-date. With more organizations relying on AI-powered systems, it’s essential for developers to prioritize security by design and implement robust testing protocols to prevent similar vulnerabilities from arising.

In light of these findings, we recommend that users take immediate action to update their Adobe and Nvidia products to the latest versions. By doing so, they can ensure their sensitive data remains protected and avoid potential risks associated with unpatched vulnerabilities.


Source: SecurityWeek — 2026-08-26