Junglewise Threat Intelligence

CVE-2026-21287: Adobe Substance3D Stager use-after-free

CVE-2026-21287 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Apple macOS, Microsoft Windows, Adobe Substance 3d Stager, Adobe Substance3D Stager. Vendors: Apple, Microsoft, Adobe.

Executive brief

Substance3D Stager is Adobe's 3D asset preparation tool used by designers and artists. A use-after-free vulnerability in versions 3.1.5 and earlier allows arbitrary code execution when a user opens a malicious file, potentially compromising creative projects and system access.

Technical details

A use-after-free vulnerability exists in Substance3D Stager versions 3.1.5 and earlier, where freed memory is incorrectly accessed during file processing. The attack requires local user interaction—specifically opening a specially crafted file. Successful exploitation results in arbitrary code execution within the context of the current user. The vulnerability is classified as high severity (CVSS 7.8), though no active exploitation in the wild has been reported at time of disclosure.

Affected products

  • Adobe Substance3D Stager 3.1.5 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats