Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain — Threadlinqs Intelligence
As of 2026-09-02, Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-2152 · Severity: CRITICAL · CVSS: 10 · Status: PATCHED · Category: VULNERABILITY
Updated: 2026-09-02 · 2 updates · revalidated 2× · latest source
Adobe shipped seven security bulletins on August 25-26, 2026 fixing 38 vulnerabilities across Campaign Classic, Content Credentials SDK/CAI, Illustrator, Substance 3D Designer/Sampler/Painter, and XD,
On August 25-26, 2026, Adobe and Nvidia both released large batches of security patches, prompting a consolidated SecurityWeek roundup. Adobe's cycle (its second of August 2026) covers seven products in seven APSB bulletins totaling 38 CVEs. The highest-impact issues sit in Adobe Campaign Classic (on-premise/hybrid ACC builds up to 7.4.4 build 9400): CVE-2026-76193 is an unauthenticated server-side request forgery (CWE-918, CVSS 10.0) with a changed scope, and CVE-2026-76195 / CVE-2026-76197 are unauthenticated OS command injection flaws (CWE-78, CVSS 10.0 each) — all three permit remote arbitrary code execution against internet-facing marketing-automation servers with no privileges and no user interaction. Adobe-hosted Campaign Classic instances were already remediated; on-premise/hybrid customers must patch. The remaining six Adobe bulletins are lower-severity but still numerous: Content Credentials SDK / Content Authenticity Initiative (CAI) libraries received 6 fixes for denial-of-service (uncontrolled resource consumption, integer underflow) and an arbitrary-filesystem-read flaw (CVE-2026-76198) triggered by opening a malicious asset; Substance 3D Sampler (10 CVEs), Substance 3D Designer (9 CVEs), and Substance 3D Painter (8 CVEs) all received near-identical batches of out-of-bounds-write / heap- and stack-based buffer overflow fixes (CVSS 7.8, CWE-787/CWE-122/CWE-121) that execute arbitrary code in the current user's context when a victim opens a malicious 3D asset file; Illustrator got one medium out-of-bounds-read information-disclosure fix (CVE-2026-71441); Adobe XD got one high-severity buffer overflow (CVE-2026-71399, CWE-120) requiring the victim to open a malicious file. Adobe states none of the 38 CVEs were known to be exploited or publicly disclosed prior to the fix.
Nvidia's parallel cycle patched 33 CVEs across five bulletins published August 4-25, 2026. The most severe cluster is NemoClaw (Nvidia's open-source reference deployment stack for running agents such as OpenClaw against a local Ollama inference backend inside Nvidia's OpenShell sandbox) and OpenShell itself: 18 CVEs, two of them critical (CVE-2026-65083, CVSS 9.9, an incomplete disallowed-inputs list in the OpenShell sandbox-provisioning API that lets a caller escape intended input restrictions; CVE-2026-65093, CVSS 9.9, a direct sandbox-escape vulnerability, CWE-427 uncontrolled search path element) and twelve rated high (7.0-8.8), spanning OS command injection in NemoClaw's status/logs plugin, NIM management component, Telegram bridge, and CLI (all CWE-78); untrusted code execution during installation and integrity-check bypasses in install/deployment scripts (CWE-494, CWE-295); a weak/legacy authentication mechanism in the remote-access helper workflow (CWE-1390); and unauthenticated access to the local inference service itself (CVE-2026-65105, CVSS 8.1) because NemoClaw binds Ollama to 0.0.0.0:11434 to let the OpenShell container reach it, which simultaneously disables Ollama's Host-header validation and exposes the unauthenticated Ollama API to the entire local network. Independent research published by Oasis Security in the days before the patch documented a full attack chain: an attacker-controlled webpage uses DNS rebinding to defeat the browser's same-origin policy, then calls Ollama's /api/show and /api/create endpoints to fetch and re-upload a model whose Go text/template has been poisoned with malicious rendering instructions — persistently hijacking the victim's local AI agent from a single page visit, no authentication required. Nvidia's other four bulletins are narrower: DGX Spark AI-computer UEFI/system firmware (5 CVEs, 3 high, requiring a privileged local attacker, out-of-bounds write and NULL-pointer-dereference primitives with a changed/escalated scope, CWE-787/CWE-476/CWE-693); Unified Fabric Manager (5 CVEs, 2 high including CVE-2026-24170, CVSS 8.8, an improper-authentication bypass via crafted HTTP requests to the web interf
Weaknesses (CWE)
CWE-918, CWE-78, CWE-77, CWE-125, CWE-787, CWE-121, CWE-122, CWE-476, CWE-426, CWE-400
Target sectors: technology, media-entertainment, manufacturing, cloud-computing, government administration
Target regions: Global
Timeline
- Ollama v0.1.29 ships a Host-header validation fix for the original DNS-rebinding vulnerability CVE-2024-28224, but the protection only applies when Ollama is bound to a loopback address — the gap NemoClaw's 0.0.0.0 binding later reopens.
- NCC Group publishes a technical advisory on CVE-2024-28224, documenting the Ollama DNS-rebinding attack pattern later re-exposed by NemoClaw's non-loopback binding.
- Adobe publishes a critical bulletin covering ColdFusion and Campaign Classic (CVE-2026-48286, build 9397 and earlier), the first of four 2026 Campaign Classic Priority-1 bulletins.
- Adobe publishes APSB26-114 (Priority 1), patching CVE-2026-48449 (incorrect authorization, CVSS 10.0, arbitrary code execution) and CVE-2026-48448 (SQL injection, CVSS 8.6, arbitrary file read) in Campaign Classic build 9397 and earlier, fixed in build 9398.
- Adobe publishes APSB26-120 (Priority 1), patching seven Campaign Classic flaws in build 9398 and earlier (fixed in build 9399), including three further CVSS 10.0 issues (CVE-2026-48331 SSRF, CVE-2026-48323 template injection, CVE-2026-48330 unauthenticated SQL injection) plus CVE-2026-48326, CVE-2026-48317, CVE-2026-48333, and CVE-2026-48399.
- Nvidia publishes bulletin 5860 for Triton Inference Server, fixing CVE-2026-47487, a medium-severity MLflow-plugin path-traversal file-access flaw.
- NemoClaw v0.0.106 introduces a proxy-level check that refuses to start against a non-loopback Ollama backend, but the enforcement covers macOS/Linux only and does not extend to Windows/WSL.
- Nvidia publishes bulletin 5817 for Cumulus Linux and NVOS, fixing three high-severity flaws: privilege escalation (CVE-2026-24183), an LLDP-daemon buffer overflow (CVE-2026-24184), and an SSH authentication-bypass in PKA-only mode (CVE-2026-24185).
- Nvidia publishes a second August Triton Inference Server bulletin fixing CVE-2026-47627, a critical (CVSS 9.8) unauthenticated path-traversal denial-of-service flaw.
- Oasis Security's technical write-up on the NemoClaw/Ollama DNS-rebinding and model-poisoning attack chain is published alongside multiple security-news outlets, ahead of/alongside Nvidia's fix.
- Nvidia publishes bulletin 5872 fixing 18 CVEs in NemoClaw and OpenShell, including two critical sandbox-related flaws (CVE-2026-65083, CVE-2026-65093, both CVSS 9.9).
- Nvidia publishes bulletin 5867 fixing five DGX Spark firmware vulnerabilities, three rated high severity, requiring UEFI update 1.110.13.
Detections & IOCs
As of 2026-09-09, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-76193, CVE-2026-76195, CVE-2026-76197, CVE-2026-71441, CVE-2026-48417, CVE-2026-48418, CVE-2026-48419, CVE-2026-48420, CVE-2026-48421, CVE-2026-48422, T1190, T1195, T1203, T1059, T1611, T1552, T1212, T1557, T1005, T1588.006