Adobe
Adobe Substance 3D Stager: vulnerabilities and CVEs
Adobe Substance 3D Stager has 87 published vulnerabilities, 22 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs87
Last 12 months22
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27309 | High (7.8) | 0.38% | — | Mar 27, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
| CVE-2026-27279 | High (7.8) | 0.26% | — | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires… |
| CVE-2026-27277 | High (7.8) | 0.38% | — | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
| CVE-2026-27276 | High (7.8) | 0.38% | — | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
| CVE-2026-27275 | High (7.8) | 0.26% | — | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires… |
| CVE-2026-27274 | High (7.8) | 0.26% | — | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires… |
| CVE-2026-27273 | High (7.8) | 0.26% | — | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires… |
| CVE-2026-21345 | High (7.8) | 0.17% | — | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker… |
| CVE-2026-21344 | High (7.8) | 0.17% | — | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker… |
| CVE-2026-21343 | High (7.8) | 0.17% | — | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker… |
| CVE-2026-21342 | High (7.8) | 0.19% | — | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires… |
| CVE-2026-21341 | High (7.8) | 0.15% | — | Feb 10, 2026 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires… |
| CVE-2026-21287 | High (7.8) | 0.21% | — | Jan 13, 2026 | Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
| CVE-2025-64531 | High (7.8) | 0.20% | — | Nov 11, 2025 | Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
| CVE-2025-61835 | High (7.8) | 0.22% | — | Nov 11, 2025 | Substance3D - Stager versions 3.1.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of… |
| CVE-2025-61834 | High (7.8) | 0.23% | — | Nov 11, 2025 | Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
| CVE-2025-61833 | High (7.8) | 0.22% | — | Nov 11, 2025 | Substance3D - Stager versions 3.1.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker… |
| CVE-2025-61807 | High (7.8) | 0.21% | — | Oct 14, 2025 | Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this… |
| CVE-2025-61806 | High (7.8) | 0.21% | — | Oct 14, 2025 | Substance3D - Stager versions 3.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker… |
| CVE-2025-61805 | High (7.8) | 0.21% | — | Oct 14, 2025 | Substance3D - Stager versions 3.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker… |
| CVE-2025-61803 | High (7.8) | 0.21% | — | Oct 14, 2025 | Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this… |
| CVE-2025-61802 | High (7.8) | 0.22% | — | Oct 14, 2025 | Substance3D - Stager versions 3.1.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
| CVE-2025-54262 | High (7.8) | 0.22% | — | Sep 16, 2025 | Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker… |
| CVE-2025-54237 | Medium (5.5) | 0.24% | — | Sep 16, 2025 | Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information.… |
| CVE-2025-54222 | High (7.8) | 0.18% | — | Aug 12, 2025 | Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires… |
| CVE-2025-27165 | Medium (5.5) | 0.19% | — | Jul 8, 2025 | Substance3D - Stager versions 3.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a… |
| CVE-2025-43571 | High (7.8) | 0.26% | — | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
| CVE-2025-43570 | High (7.8) | 0.26% | — | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
| CVE-2025-43569 | High (7.8) | 0.22% | — | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires… |
| CVE-2025-43568 | High (7.8) | 0.26% | — | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.