Junglewise Threat Intelligence

CVE-2026-27275: Adobe Substance3D Stager out-of-bounds write

CVE-2026-27275 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Adobe Substance 3d Stager, Apple macOS, Microsoft Windows, Adobe Substance3D Stager. Vendors: Adobe, Apple, Microsoft.

Executive brief

Substance3D Stager is Adobe's 3D asset creation and staging software. Versions 3.1.7 and earlier contain an out-of-bounds write flaw that allows an attacker to execute arbitrary code with the privileges of the user running the application, triggered by opening a malicious file.

Technical details

This is an out-of-bounds write vulnerability in Adobe Substance3D Stager versions 3.1.7 and earlier. The vulnerability allows arbitrary code execution in the context of the current user. Exploitation requires user interaction—specifically, the victim must open a malicious file. No network vector is involved; the attack is local and user-initiated. An attacker can achieve arbitrary code execution with the victim's privileges by crafting a malicious file and socially engineering the user to open it.

Affected products

  • Adobe Substance3D Stager 3.1.7 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats