Junglewise Threat Intelligence

CVE-2026-27309: Adobe Substance3D Stager use-after-free

CVE-2026-27309 · Severity: high · CVSS 7.8 · Published 2026-03-27

Technologies: Apple macOS, Microsoft Windows, Adobe Substance 3d Stager, Adobe Substance3D Stager. Vendors: Apple, Microsoft, Adobe.

Executive brief

Substance3D Stager is a 3D design and prototyping tool used by creative professionals. A use-after-free vulnerability in versions 3.1.7 and earlier allows attackers to execute arbitrary code when a victim opens a malicious file, potentially compromising creative projects and system data.

Technical details

The vulnerability is a use-after-free defect in Substance3D Stager that permits arbitrary code execution within the context of the current user. The flaw requires user interaction—specifically, a victim must open a malicious file to trigger the vulnerability. This attack vector means the vulnerability is not remotely exploitable without social engineering. Affected versions are 3.1.7 and earlier. A patch is expected via Adobe's APSB26-29 bulletin (currently access-restricted), indicating a fix is available or forthcoming.

Affected products

  • Adobe Substance3D Stager 3.1.7 and earlier

Timeline

  • 2026-03-27: disclosed

References

Related threats