Adobe and Nvidia on Tuesday announced patches for dozens of vulnerabilities affecting their products, including flaws rated critical severity.
Nvidia
Nvidia published four new advisories on Tuesday. One advisory alerts customers to 18 security vulnerabilities in NemoClaw and OpenShell, enterprise AI security and runtime infrastructure products designed to wrap around autonomous AI agents.
Two of the vulnerabilities are critical and they can be exploited for code execution, privilege escalation, data tampering, information disclosure, and denial of service (DoS).
A dozen of the other weaknesses have a high severity rating and their exploitation can have a similar impact. Cyera has detailed one of these vulnerabilities, showing how it can be exploited to hijack AI agents.
Five vulnerabilities have been resolved by Nvidia in its DGX Spark AI computer, including three high-severity flaws that can be exploited for code execution, privilege escalation, data tampering, and DoS.
In the Unified Fabric Manager platform, the tech giant fixed two high- and three medium-severity issues that, if exploited, could lead to code execution and privilege escalation.
The fourth advisory addresses Rohammer attacks against Nvidia GPUs, with the vendor providing additional mitigation advice.