
Substance3D - Stager | Use After Free (CWE-416) CVE: CVE-2026-27276 Vendor: Adobe Product: Substance3D - Stager CVSS: 7.8 Credits: n/a Description: Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27276 • https://helpx.adobe.com/security/products/substance3d_stager/apsb26-29.html #dbugs_vuln
Post summary
Adobe disclosed a Use‑After‑Free vulnerability (CVE‑2026‑27276) in Substance3D Stager that can lead to arbitrary code execution. A vendor advisory is available to apply the patch.



