« Back to list

Adobe

Adobe Substance 3D Stager: vulnerabilities and CVEs

Adobe Substance 3D Stager has 87 published vulnerabilities, 22 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs87
Last 12 months22
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-27309High (7.8)0.38%—Mar 27, 2026
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
CVE-2026-27279High (7.8)0.26%—Mar 10, 2026
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
CVE-2026-27277High (7.8)0.38%—Mar 10, 2026
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
CVE-2026-27276High (7.8)0.38%—Mar 10, 2026
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
CVE-2026-27275High (7.8)0.26%—Mar 10, 2026
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
CVE-2026-27274High (7.8)0.26%—Mar 10, 2026
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
CVE-2026-27273High (7.8)0.26%—Mar 10, 2026
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
CVE-2026-21345High (7.8)0.17%—Feb 10, 2026
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker…
CVE-2026-21344High (7.8)0.17%—Feb 10, 2026
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker…
CVE-2026-21343High (7.8)0.17%—Feb 10, 2026
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker…
CVE-2026-21342High (7.8)0.19%—Feb 10, 2026
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
CVE-2026-21341High (7.8)0.15%—Feb 10, 2026
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
CVE-2026-21287High (7.8)0.21%—Jan 13, 2026
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
CVE-2025-64531High (7.8)0.20%—Nov 11, 2025
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
CVE-2025-61835High (7.8)0.22%—Nov 11, 2025
Substance3D - Stager versions 3.1.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…
CVE-2025-61834High (7.8)0.23%—Nov 11, 2025
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
CVE-2025-61833High (7.8)0.22%—Nov 11, 2025
Substance3D - Stager versions 3.1.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker…
CVE-2025-61807High (7.8)0.21%—Oct 14, 2025
Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…
CVE-2025-61806High (7.8)0.21%—Oct 14, 2025
Substance3D - Stager versions 3.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker…
CVE-2025-61805High (7.8)0.21%—Oct 14, 2025
Substance3D - Stager versions 3.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker…
CVE-2025-61803High (7.8)0.21%—Oct 14, 2025
Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…
CVE-2025-61802High (7.8)0.22%—Oct 14, 2025
Substance3D - Stager versions 3.1.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
CVE-2025-54262High (7.8)0.22%—Sep 16, 2025
Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker…
CVE-2025-54237Medium (5.5)0.24%—Sep 16, 2025
Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information.…
CVE-2025-54222High (7.8)0.18%—Aug 12, 2025
Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
CVE-2025-27165Medium (5.5)0.19%—Jul 8, 2025
Substance3D - Stager versions 3.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a…
CVE-2025-43571High (7.8)0.26%—May 13, 2025
Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
CVE-2025-43570High (7.8)0.26%—May 13, 2025
Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
CVE-2025-43569High (7.8)0.22%—May 13, 2025
Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
CVE-2025-43568High (7.8)0.26%—May 13, 2025
Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter42
  2. T1203 Exploitation for Client Execution42

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Adobe