
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21344 is an out-of-bounds read vulnerability in Adobe Substance 3D Stager that can allow an attacker to execute arbitrary code in the context of the current user. It affects Substance 3D Stager versions 3.1.6 and earlier (all versions prior to 3.1.7). Adobe disclosed and patched this vulnerability on February 10, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and is triggered during the parsing of a specially crafted file. When processing such a file, the application reads past the end of an allocated memory structure, which can be leveraged to achieve code execution. Exploitation requires local access and user interaction — specifically, a victim must be tricked into opening a malicious file — and no elevated privileges are required (Adobe Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code in the context of the current user, potentially compromising confidentiality, integrity, and availability of the affected system. Since the attack vector is local and requires user interaction, the blast radius is limited to the victim's user session, but could enable further lateral movement if the compromised account has elevated privileges. No scope change beyond the affected application is expected based on the CVSS assessment (Adobe Advisory).
.sbs, .sbsar, or proprietary Stager formats) received via email or downloaded from untrusted sources.cmd.exe, powershell.exe, bash, curl, or network-connecting processes).Adobe has released Substance 3D Stager version 3.1.7 to address this vulnerability; users should update immediately. As an interim workaround, users should avoid opening Stager files from untrusted or unknown sources. Organizations may also consider restricting file-opening permissions or applying application sandboxing where feasible (Adobe Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple Adobe product vulnerabilities patched in February 2026, including this one, could allow for arbitrary code execution. Coverage has been limited to standard vulnerability tracking and aggregation platforms, with no notable independent researcher commentary or significant social media discussion observed, consistent with the low EPSS score and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."