CVE-2026-27277
published 2026-03-10CVE-2026-27277: Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of…
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.17%
6.5th percentile
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | substance3d_stager | <= 3.1.7 | — |
| adobe | substance_3d_stager | < 3.1.8 | 3.1.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-27275 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27275 [HIGH] CVE-2026-27275 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27275 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Add
Wiz
CVE-2026-21345 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21345 [HIGH] CVE-2026-21345 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21345 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.3
Exploitation Probability (
Wiz
CVE-2026-27273 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27273 [HIGH] CVE-2026-27273 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27273 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Add
Wiz
CVE-2026-27279 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27279 [HIGH] CVE-2026-27279 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27279 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Add
Wiz
CVE-2026-27309 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27309 [HIGH] CVE-2026-27309 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27309 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 27, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Added at
Wiz
CVE-2026-21343 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21343 [HIGH] CVE-2026-21343 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21343 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.3
Exploitation Probability (
Wiz
CVE-2026-27274 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27274 [HIGH] CVE-2026-27274 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27274 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Add
Wiz
CVE-2026-21287 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21287 [HIGH] CVE-2026-21287 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21287 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published January 13, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Added
Wiz
CVE-2026-21342 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21342 [HIGH] CVE-2026-21342 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21342 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix
Wiz
CVE-2026-27276 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27276 [HIGH] CVE-2026-27276 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27276 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Added at
Wiz
CVE-2026-21344 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21344 [HIGH] CVE-2026-21344 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21344 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.3
Exploitation Probability (
Wiz
CVE-2026-21341 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21341 [HIGH] CVE-2026-21341 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21341 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix
Wiz
CVE-2026-27277 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-27277 [HIGH] CVE-2026-27277 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27277 :
Adobe Substance 3D Stager vulnerability analysis and mitigation
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Adobe Substance 3D Stager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:substance_3d_stager
Sources
Windows Severity HIGH Has Fix Added at
Bugzilla
CVE-2026-15685 Ollama: Ollama: Denial of Service via improper array index validation in downloadBlob function
bugzilla·2026-07-13·CVSS 7.5
CVE-2026-15685 [HIGH] CVE-2026-15685 Ollama: Ollama: Denial of Service via improper array index validation in downloadBlob function
CVE-2026-15685 Ollama: Ollama: Denial of Service via improper array index validation in downloadBlob function
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated array. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-27277.
2026-03-10
Published