CVE-2026-27276
published 2026-03-10CVE-2026-27276: Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of…
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.17%
6.6th percentile
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | substance3d_stager | <= 3.1.7 | — |
| adobe | substance_3d_stager | < 3.1.8 | 3.1.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-27275 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27275 [HIGH] CVE-2026-27275 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27275 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Add
Wiz
CVE-2026-21345 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21345 [HIGH] CVE-2026-21345 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21345 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.3
Exploitation Probability (
Wiz
CVE-2026-27273 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27273 [HIGH] CVE-2026-27273 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27273 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Add
Wiz
CVE-2026-27279 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27279 [HIGH] CVE-2026-27279 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27279 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Add
Wiz
CVE-2026-27309 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27309 [HIGH] CVE-2026-27309 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27309 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 27, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Added at
Wiz
CVE-2026-21343 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21343 [HIGH] CVE-2026-21343 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21343 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.3
Exploitation Probability (
Wiz
CVE-2026-27274 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27274 [HIGH] CVE-2026-27274 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27274 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Add
Wiz
CVE-2026-21287 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21287 [HIGH] CVE-2026-21287 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21287 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published January 13, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Added
Wiz
CVE-2026-21342 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21342 [HIGH] CVE-2026-21342 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21342 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix
Wiz
CVE-2026-27276 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27276 [HIGH] CVE-2026-27276 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27276 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Added at
Wiz
CVE-2026-21344 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21344 [HIGH] CVE-2026-21344 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21344 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.3
Exploitation Probability (
Wiz
CVE-2026-21341 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21341 [HIGH] CVE-2026-21341 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21341 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix
Wiz
CVE-2026-27277 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27277 [HIGH] CVE-2026-27277 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27277 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Added at
2026-03-10
Published