CVE-2026-21339
published 2026-02-10CVE-2026-21339: Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.15%
4.9th percentile
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | substance3d_designer | <= 15.1.0 | — |
| adobe | substance_3d_designer | < 15.1.2 | 15.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21334 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21334 [HIGH] CVE-2026-21334 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21334 :
Adobe Substance 3D Designer vulnerability analysis and mitigation
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Designer
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_designer
Sources
Windows Severity HIGH
Wiz
CVE-2026-21307 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21307 [HIGH] CVE-2026-21307 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21307 :
Adobe Substance 3D Designer vulnerability analysis and mitigation
Substance3D - Designer versions 15.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published January 13, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Designer
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_designer
Sources
Windows Severity HIGH
Wiz
CVE-2026-21337 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21337 [MEDIUM] CVE-2026-21337 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21337 :
Adobe Substance 3D Designer vulnerability analysis and mitigation
Substance3D - Designer versions 15.1.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Substance 3D Designer
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:su
Wiz
CVE-2026-21340 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21340 [MEDIUM] CVE-2026-21340 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21340 :
Adobe Substance 3D Designer vulnerability analysis and mitigation
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Substance 3D Designer
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:
Wiz
CVE-2026-21336 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21336 [MEDIUM] CVE-2026-21336 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21336 :
Adobe Substance 3D Designer vulnerability analysis and mitigation
Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Substance 3D Designer
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.6
Exploitation Probability (EPSS) N/A
Affected packages and lib
Wiz
CVE-2026-21308 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21308 [MEDIUM] CVE-2026-21308 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21308 :
Adobe Substance 3D Designer vulnerability analysis and mitigation
Substance3D - Designer versions 15.0.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published January 13, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Substance 3D Designer
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:s
Wiz
CVE-2026-21339 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21339 [MEDIUM] CVE-2026-21339 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21339 :
Adobe Substance 3D Designer vulnerability analysis and mitigation
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Substance 3D Designer
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:
Wiz
CVE-2026-21335 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21335 [HIGH] CVE-2026-21335 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21335 :
Adobe Substance 3D Designer vulnerability analysis and mitigation
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Designer
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_designer
Sources
Windows Severity HIGH
Wiz
CVE-2026-21338 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21338 [MEDIUM] CVE-2026-21338 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21338 :
Adobe Substance 3D Designer vulnerability analysis and mitigation
Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 5.5
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Substance 3D Designer
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.6
Exploitation Probability (EPSS) N/A
Affected packages and lib
2026-02-10
Published