Nvidia issued four new advisories, addressing 18 security vulnerabilities in its NemoClaw and OpenShell enterprise AI security and runtime infrastructure products. Two of these vulnerabilities are critical and could lead to code execution, privilege escalation, data tampering, information disclosure, and denial of service (DoS). Twelve other weaknesses were rated high severity with similar potential impacts, with one vulnerability detailed by Cyera showing how it could hijack AI agents.
Additionally, Nvidia resolved five vulnerabilities in its DGX Spark AI computer, including three high-severity flaws that could enable code execution, privilege escalation, data tampering, and DoS. The company also fixed two high- and three medium-severity issues in its Unified Fabric Manager platform, which could result in code execution and privilege escalation. A fourth advisory provided mitigation advice for Rohammer attacks against Nvidia GPUs.
Adobe released seven new security advisories, addressing dozens of vulnerabilities across its product line. Critical code execution vulnerabilities were patched in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD, and Campaign Classic. DoS and information exposure flaws were also fixed in Illustrator and Content Credentials SDK.
Adobe stated that none of these vulnerabilities have been exploited in the wild. However, the Campaign Classic advisory received a priority rating of 1, indicating a higher risk of exploitation compared to the others.
These patches are crucial for users of Adobe and Nvidia products to protect against potential security breaches. The vulnerabilities, particularly those rated critical and high, could allow attackers to gain unauthorized access, manipulate data, or disrupt services. Applying these updates promptly is a recommended security practice to maintain system integrity and data confidentiality.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Adobe and Nvidia have released patches addressing dozens of vulnerabilities, including critical flaws, across various products. These updates are important for users to apply to mitigate risks such as code execution, privilege escalation, and data tampering.