Use After Free Vulnerability in Substance3D Stager by Adobe
CVE-2026-21287
7.8HIGH
What is CVE-2026-21287?
Substance3D Stager is at risk due to a Use After Free vulnerability present in versions 3.1.5 and earlier. This flaw allows for arbitrary code execution under the permissions of the current user, posing significant security risks if exploited. The successful exploitation requires user interaction, specifically that a victim must open a malicious file crafted to trigger this vulnerability.
Affected Version(s)
Substance3D - Stager 0 <= 3.1.5