Junglewise Threat Intelligence

CVE-2026-71564: Adobe Substance3D Designer out-of-bounds write

CVE-2026-71564 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Adobe Substance3D Designer, a professional 3D design and content creation tool, is affected by an out-of-bounds write vulnerability. An attacker could exploit this flaw by crafting a malicious file that, when opened by a user, executes arbitrary code with the privileges of the logged-in designer, potentially compromising the user's system and access to design assets.

Technical details

This vulnerability is an out-of-bounds write flaw in Adobe Substance3D Designer that can lead to arbitrary code execution in the user's security context. The vulnerability requires user interaction, as a victim must open a specially crafted malicious file to trigger the exploit. The out-of-bounds write occurs during file processing, allowing an attacker to overwrite memory and redirect execution flow. No information is available on patch status from the provided references, though Adobe typically issues security updates through their APSB advisories.

Affected products

  • Adobe Substance3D Designer

Timeline

  • 2026-08-25: disclosed

References

Related threats