Adobe and Nvidia Patch Dozens of Vulnerabilities
Nvidia disclosed 18 security vulnerabilities across NemoClaw and OpenShell, enterprise AI security products for autonomous agents, with two critical flaws enabling code execution, privilege escalation, and DoS Adobe patched critical code execution vulnerabilities in Substance 3D suite, XD, and Campaign Classic, along with DoS and information exposure flaws in Illustrator and Content Credentials SDK Both companies are intensifying security patch cycles, with Adobe moving to bi-monthly advisories
Analysis
TL;DR
- Nvidia disclosed 18 security vulnerabilities across NemoClaw and OpenShell, enterprise AI security products for autonomous agents, with two critical flaws enabling code execution, privilege escalation, and DoS
- Adobe patched critical code execution vulnerabilities in Substance 3D suite, XD, and Campaign Classic, along with DoS and information exposure flaws in Illustrator and Content Credentials SDK
- Both companies are intensifying security patch cycles, with Adobe moving to bi-monthly advisories and Nvidia releasing multiple advisories in rapid succession across its AI infrastructure stack
- Cyera demonstrated a real-world exploit chain for hijacking AI agents through one of Nvidia's disclosed vulnerabilities, highlighting active threat landscape
- Nvidia also addressed Rohammer attacks against GPUs and patched vulnerabilities in Triton Inference Server, Cumulus Linux, and NVOS
Why It Matters
This represents a significant convergence of AI infrastructure and enterprise software security concerns, as autonomous AI agents become more widely deployed in production environments. The disclosure of exploitable vulnerabilities in Nvidia's NemoClaw and OpenShell—products specifically designed to secure AI agents—signals that the AI security layer itself is becoming a target, raising urgent questions about trust in enterprise AI deployments.
Technical Details
- Nvidia NemoClaw & OpenShell: 18 vulnerabilities disclosed, including 2 critical and 12 high-severity flaws. Attack vectors include code execution, privilege escalation, data tampering, information disclosure, and denial of service. Cyera published a detailed proof-of-concept demonstrating AI agent hijacking through one of these vulnerabilities.
- Nvidia DGX Spark: 5 vulnerabilities fixed, including 3 high-severity flaws affecting code execution, privilege escalation, data tampering, and DoS capabilities.
- Nvidia Unified Fabric Manager: 2 high-severity and 3 medium-severity issues patched that could enable code execution and privilege escalation.
- Rohammer Attacks: Nvidia issued a fourth advisory providing additional mitigation guidance against Rohammer side-channel attacks targeting NVIDIA GPUs.
- Adobe Critical Patches: Code execution vulnerabilities patched in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD, and Campaign Classic. DoS and information exposure flaws fixed in Illustrator and Content Credentials SDK. Campaign Classic flagged as priority 1 (highest exploitation risk). No vulnerabilities reported as exploited in the wild.
Industry Insight
- The rapid-fire disclosure pattern from both Nvidia and Adobe suggests the AI supply chain is entering a period of intense security scrutiny, and organizations relying on these platforms should prioritize patching NemoClaw, OpenShell, and Adobe Creative Cloud products immediately.
- The Cyera demonstration of AI agent hijacking validates emerging threat models around autonomous AI systems—security teams should treat AI agent runtime environments as critical attack surfaces and implement zero-trust principles for agent-to-infrastructure communication.
- Adobe's shift to bi-monthly security advisories and the concentration of critical flaws in enterprise products (Campaign Classic, Substance 3D) indicates that creative and enterprise software stacks are becoming increasingly attractive targets, warranting closer integration of security testing into AI-assisted development pipelines.
Disclaimer: The above content is generated by AI and is for reference only.