Adobe and Nvidia Fix Dozens of Security Flaws, Including Critical Bugs That Could Let Attackers Take Control

Both companies released patches on the same Tuesday, covering vulnerabilities across AI tools, design software, and marketing platforms. Some flaws are rated critical, meaning attackers could run their own code on affected machines.

ThreatVectr Newsdesk· 3 min read
Extreme close-up of a glowing server rack in a dark data centre, amber and blue indicator lights reflecting off brushed metal chassis, shallow depth of field dr
Share

Key points

  • Nvidia patched 18 vulnerabilities in its NemoClaw and OpenShell AI products on Tuesday, two of them rated critical severity.
  • Adobe released seven separate security advisories on the same day, fixing critical code-execution flaws across five products.
  • Adobe confirmed none of the vulnerabilities it patched this week have been exploited in the wild.
  • Nvidia's DGX Spark AI computer received fixes for five vulnerabilities, three of them high severity.
  • Adobe's Campaign Classic advisory carries its highest risk rating, a Priority 1, meaning attackers are considered more likely to target it.

Two major technology companies pushed out security fixes on the same Tuesday, covering a wide sweep of products used by businesses, creative professionals, and AI developers.

What did Nvidia fix, and should businesses worry?

Nvidia's most serious patches cover NemoClaw and OpenShell, two products designed to manage and secure autonomous AI agents (software that can carry out tasks on a computer without a human clicking each step). Eighteen vulnerabilities were found across those two products. Two are rated critical.

A critical-severity vulnerability is one where an attacker, if they reach the affected software, could run their own code on that machine, steal data, gain administrator-level control, or crash the system outright. All of those outcomes are possible here.

Nvidia also fixed five vulnerabilities in the DGX Spark, a specialised computer built for AI workloads. Three of those five carry high-severity ratings and share similar risks: code execution, privilege escalation (where an attacker gains more control than they should have), and denial-of-service attacks (where the system is flooded with requests until it stops responding).

A separate fix addresses the Unified Fabric Manager, a platform that coordinates networks of AI and graphics processors, resolving two high-severity and three medium-severity issues.

Nvidia also flagged a class of attack called Rowhammer against its graphics cards (GPUs). Rowhammer is a technique where rapidly reading from one part of a computer's memory causes errors in a neighbouring section, potentially allowing an attacker to change data the machine thought was protected. Nvidia provided guidance on reducing that risk but did not issue a software patch.

What did Adobe fix?

Adobe patched critical code-execution flaws in five products: Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter (three tools widely used by artists and product designers to create three-dimensional images), XD (a user-interface design tool), and Campaign Classic (an email and marketing automation platform used by large organisations).

Code execution flaws are serious because they can let an attacker take control of a machine simply by getting a user to open a crafted file or visit a prepared page.

Adobe's Illustrator drawing software and Content Credentials SDK (a software toolkit for verifying whether images are AI-generated) received fixes for less severe denial-of-service and information-exposure bugs.

Adobe confirmed none of this week's vulnerabilities are being actively exploited. Even so, Campaign Classic received a Priority 1 rating under Adobe's own risk scale, the company's way of signalling that a product is a more attractive target and that organisations should apply the patch quickly.

What should affected organisations do now?

Apply the patches. That is the short answer. Both companies have published the fixes; the risk window shrinks the moment they are installed.

Organisations running Adobe Campaign Classic should treat this as urgent given the Priority 1 rating. Teams using Nvidia's NemoClaw or OpenShell in AI pipelines should check Nvidia's published advisories and follow the recommended update steps. Smaller businesses using Adobe's design tools face lower immediate risk but should schedule updates during the next maintenance window.

© 2026 Threat Vectr