Junglewise Threat Intelligence

CVE-2026-27277: Adobe Substance3D Stager use-after-free vulnerability

CVE-2026-27277 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Apple macOS, Microsoft Windows, Adobe Substance 3d Stager, Adobe Substance3D Stager. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe Substance3D Stager is a 3D design and staging tool used by creative professionals. Versions 3.1.7 and earlier contain a use-after-free memory flaw that allows attackers to execute arbitrary code with the privileges of the current user if they trick a victim into opening a malicious file. This could lead to data theft, malware installation, or compromise of creative assets and projects.

Technical details

The vulnerability is a use-after-free condition in Adobe Substance3D Stager versions 3.1.7 and earlier. It allows arbitrary code execution in the context of the current user. Exploitation requires user interaction—specifically, a victim must open a malicious file in the affected software. No network attack vector or authentication bypass is required. Upon successful exploitation, an attacker can execute arbitrary code with the privileges of the user running the application. Patches are expected via Adobe security updates for versions after 3.1.7.

Affected products

  • Adobe Substance3D Stager 3.1.7 and earlier

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory: APSB26-29 security update published

References

Related threats