
Substance3D Painter ≤11.1.2 and Stager ≤3.1.7 are affected by CVE-2026-21365 and CVE-2026-27276, enabling memory exposure and code execution via malicious files. Users should update promptly. https://threatcluster.io/cluster/multiple-vulnerabilities-found-in-substance3d-software-d4441333
Post summary
The entry reports that Substance3D Painter and Stager versions are vulnerable to CVE-2026-21365 and CVE-2026-27276, which allow memory exposure and code execution through malicious files, and urges users to apply updates.


