AI Agent Flaws, GPU Attacks Put Patch Cycles on Notice
Adobe and Nvidia address dozens of vulnerabilities, including critical flaws in AI infrastructure and GPU attack mitigations.
Patch Tuesday arrived with a familiar rhythm for enterprise defenders: two of the biggest names in enterprise software and hardware, Adobe and Nvidia, each pushing out a slate of fixes. But this week's updates are less about routine housekeeping and more about the shifting ground beneath security teams — AI agents, GPU-adjacent attack surfaces, and the quiet cadence of twice-monthly updates.
Nvidia's AI Infrastructure in the Crosshairs
Nvidia published four new advisories on Tuesday, with the most significant clustering around its AI-focused product lines. One advisory covers 18 security vulnerabilities in NemoClaw and OpenShell, products described as enterprise AI security and runtime infrastructure designed to wrap around autonomous AI agents. Of those, two are rated critical severity, and a dozen more carry a high severity rating.
According to the advisories, these flaws could be exploited for code execution, privilege escalation, data tampering, information disclosure, and denial of service (DoS). Nvidia's partners are already examining the real-world impact; Cyera has detailed one of these vulnerabilities, showing how it could be exploited to hijack AI agents.
DGX Spark and Fabric Manager Fixes
Nvidia also resolved five vulnerabilities in its DGX Spark AI computer, including three high-severity flaws that, like those in NemoClaw, could lead to code execution, privilege escalation, data tampering, and denial of service. Meanwhile, in the Unified Fabric Manager platform, the company fixed two high- and three medium-severity issues that, if exploited, could also result in code execution and privilege escalation.
The breadth of affected components — from runtime infrastructure to management planes — points to a wider attack surface than many organizations might realize when they deploy AI-adjacent systems. Nvidia's advisory language doesn't sugarcoat the impact: these are flaws that could give an attacker a foothold in the very systems designed to secure and run AI workloads.
GPU Rowhammer Attacks Get a Refresh
Nvidia's fourth advisory addresses Rohammer attacks against Nvidia GPUs. A Nvidia note provides additional mitigation advice for this class of attack, which researchers have shown can be used to achieve root shell access on vulnerable systems.
The advisory doesn't introduce new patch levels, but it serves as a reminder that GPU-specific attack techniques are part of the threat landscape. Rowhammer, a hardware vulnerability, is not new, but its application to GPUs is a relatively recent concern for defenders who typically focus on software patches.
Triton and Earlier Advisories
In addition to the advisories published this week, Nvidia informed customers last week about five vulnerabilities in Triton Inference Server, including flaws that can allow arbitrary code execution. The company communicated the same day about privilege escalation and code execution vulnerabilities patched in Cumulus Linux and NVOS.
This isn't a one-off release. Nvidia has been steadily patching its AI stack, from the training to inference layers, and this week's batch continues that pattern. The critical and high-severity ratings on the NemoClaw and OpenShell flaws suggest that attackers are paying close attention to AI deployment infrastructures.
Adobe's Twice-a-Month Rhythm
Adobe, meanwhile, is now publishing security advisories twice a month, and on Tuesday it released seven new advisories addressing dozens of vulnerabilities. The company has patched critical code execution vulnerabilities in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD, and Campaign Classic.
Adobe also fixed denial of service and information exposure flaws in Illustrator and Content Credentials SDK. The breadth of products affected — from creative tools to marketing campaign platforms — reflects the wide range of software Adobe maintains, and the challenges of keeping them all secure.
Patch Timing and Exploitation Risk
Adobe says none of the vulnerabilities have been exploited in the wild, and only the Campaign Classic advisory has a priority rating of 1, indicating it's at higher risk of exploitation. That's a critical nuance for defenders: not all patches are created equal, and the company is signaling which one needs immediate attention.
The Campaign Classic flaw, given its priority rating, is the one to prioritize despite the lack of observed exploits. The other fixes, while still important, carry a lower immediate risk in Adobe's assessment.
Nvidia and Adobe are not the only vendors in the news. SecurityWeek has been tracking a series of related developments, including Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities and a flaw in an Adobe extension that enabled WhatsApp data theft.
Key Numbers in This Patch Cycle
- 18 vulnerabilities in NemoClaw and OpenShell
- 2 critical flaws in NemoClaw and OpenShell
- 5 vulnerabilities resolved in DGX Spark
- 7 Adobe security advisories released
- 5 vulnerabilities in Triton Inference Server
Why It Matters for Defenders
This patch cycle underscores that security teams can no longer assume that AI infrastructure is a separate, isolated concern. With critical flaws in tools designed to orchestrate AI agents, and with GPU-specific attack techniques getting more attention, the attack surface is expanding beyond traditional servers and endpoints. The fact that Nvidia is patching these products regularly suggests they are becoming a target, and that defenders need to be just as diligent about patching AI infrastructure as they are about operating systems and applications.
The pace of Adobe's updates — now twice a month — also signals a reality about modern software: vulnerabilities will keep coming, and the risks of exploitation are always present, even if no active attacks have been observed yet. For organizations, this means that a patch management strategy that is tied to a monthly cycle may no longer be sufficient. The cadence of vendor updates is accelerating, and the gap between patch release and exploitation is shrinking.
The lack of any known exploitation for the Adobe flaws is good news, but it's no reason for complacency. The priority rating on Campaign Classic is a reminder that attackers often scan for newly patched vulnerabilities within days of disclosure. The next few weeks will be telling: whether we see exploit attempts against these latest fixes, or whether the patch-and-pray cycle continues to hold.
Sources
- SecurityWeek Original source
- Nvidia Also reporting
- detailed Also reporting
- Rohammer attacks against Nvidia GPUs Also reporting
- Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities Also reporting
- Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft Also reporting
Continue Reading
ATF's 'Major Incident' After Qilin Breach Claims
ATF confirms a standalone system was breached, described as a "major incident" amid Qilin ransomware claims.
CISA KEV Adds Six Flaws, NetScaler Web Shells Spotted
CISA adds six exploited flaws to KEV, including NetScaler, Linux, and SQL Server bugs.
Zero-click RCE in Avada leaves million sites exposed
A 9.8-rated flaw chain in the Avada WordPress theme lets unauthenticated attackers run PHP code.