Adobe and Nvidia Fix Dozens of Security Flaws, Including Critical Bugs That Could Let Attackers Take Control
Both companies released patches on the same Tuesday, covering vulnerabilities across AI tools, design software, and marketing platforms. Some flaws are rated critical, meaning attackers could run their own code on affected machines.

Key points
- Nvidia patched 18 vulnerabilities in its NemoClaw and OpenShell AI products on Tuesday, two of them rated critical severity.
- Adobe released seven separate security advisories the same day, fixing critical code-execution flaws across five products.
- Adobe confirmed none of the vulnerabilities it patched this week have been exploited in the wild.
- Nvidia's DGX Spark AI computer received fixes for five vulnerabilities, three of them high severity.
- Adobe's Campaign Classic advisory carries a Priority 1 rating, meaning attackers are considered more likely to target it.
Two major technology companies pushed out security fixes on the same Tuesday, covering a wide sweep of products used by businesses and AI developers.
What did Nvidia fix, and should businesses worry?
Nvidia's most serious patches cover NemoClaw and OpenShell, two products designed to manage and secure autonomous AI agents (software that can carry out tasks on a computer without a human clicking each step). Eighteen vulnerabilities were found across those two products, two rated critical and a dozen more rated high severity. Exploitation of either tier could enable code execution, privilege escalation, data tampering or denial-of-service attacks.
We've followed NemoClaw's security record closely: our 25 August story reported that a single malicious webpage can quietly take over a local AI agent, so today's patches land in a product that researchers were already treating as a live target.
Nvidia also fixed five vulnerabilities in the DGX Spark, a specialised computer built for AI workloads. Three of those five carry high-severity ratings and share similar risks: code execution, privilege escalation (where an attacker gains more control than they should), and denial-of-service attacks (where a system is flooded with requests until it stops responding).
A separate fix addresses the Unified Fabric Manager, a platform that coordinates networks of AI and graphics processors, resolving two high-severity issues alongside three medium-severity ones.
Nvidia also flagged a class of attack called Rowhammer against its graphics cards. Rowhammer is a technique where rapidly reading from one part of a computer's memory causes errors in a neighbouring section, potentially letting an attacker alter data the machine thought was protected. Nvidia provided mitigation guidance but didn't issue a software patch.
What did Adobe fix?
Adobe patched critical code-execution flaws in five products: Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter (tools widely used by artists to create three-dimensional images), XD (a user-interface design tool), and Campaign Classic (an email and marketing automation platform used by large organisations). Illustrator and the Content Credentials SDK, a toolkit for verifying whether images are AI-generated, received fixes for less severe denial-of-service and information-exposure bugs.
None of this week's vulnerabilities are being actively exploited. Campaign Classic's Priority 1 rating is Adobe's signal that a product is a more attractive target and that the patch should go in fast. That rating is consistent with what we've seen before: Campaign Classic has appeared in four of our advisories since 3 July, including a perfect-ten severity flaw patched on 1 August that required no user interaction to exploit.
What should affected organisations do now?
Apply the patches. Both companies have published the fixes; the risk window shrinks the moment they're installed.
Organisations running Campaign Classic should treat this as urgent. Teams using NemoClaw or OpenShell should check Nvidia's published advisories and follow the recommended update steps. Businesses using Adobe's design tools face lower immediate risk but should schedule updates in the next maintenance window.



