Junglewise Threat Intelligence

CVE-2026-27276: Adobe Substance3D Stager use-after-free

CVE-2026-27276 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Apple macOS, Microsoft Windows, Adobe Substance 3d Stager, Adobe Substance3D Stager. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe Substance3D Stager is a 3D asset management tool used by designers and creative professionals. Versions 3.1.7 and earlier contain a memory safety vulnerability that allows attackers to execute arbitrary code on a user's system by tricking them into opening a malicious file, potentially compromising the user's data and system security.

Technical details

The vulnerability is a use-after-free defect in Substance3D Stager versions 3.1.7 and earlier. This memory safety issue occurs when the application references memory that has already been freed, allowing an attacker to corrupt memory state and achieve arbitrary code execution. The attack requires user interaction—specifically, a victim must open a malicious file to trigger the flaw. The vulnerability is network-adjacent in that files could be delivered via email or download, but local exploitation context (running in the current user's privilege level) applies once the file is opened. Adobe has released security updates to address this issue.

Affected products

  • Adobe Substance3D Stager 3.1.7 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats