
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27309 is a Use After Free (UAF) vulnerability in Adobe Substance 3D Stager versions 3.1.7 and earlier that can result in arbitrary code execution in the context of the current user. The vulnerability was disclosed by Adobe on March 10, 2026, and published to NVD on March 27, 2026. It carries a CVSS v3.1 base score of 7.8 (High), with a local attack vector requiring user interaction (Adobe Advisory).
The vulnerability is classified as CWE-416 (Use After Free), a memory corruption condition where a program continues to use a pointer after the referenced memory has been freed. Exploitation requires a victim to open a specially crafted malicious file, triggering the UAF condition within Substance 3D Stager's file parsing logic. No privileges are required on the part of the attacker beyond delivering the malicious file to the victim. No public technical write-ups or proof-of-concept code have been identified at this time (Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code at the privilege level of the current user, potentially resulting in full compromise of the user's session, data exfiltration, and installation of malware. All three security dimensions — confidentiality, integrity, and availability — are rated High. The attack is scoped to the local system and does not inherently enable privilege escalation beyond the current user context, though it could serve as a foothold for further lateral movement (Adobe Advisory).
cmd.exe, powershell.exe, bash, curl, or other shells/utilities).Adobe has released Substance 3D Stager version 3.1.8 to address this vulnerability; users should upgrade immediately. As a workaround prior to patching, users should avoid opening Stager project files from untrusted or unknown sources. Organizations may also consider implementing application whitelisting or restricting execution of Substance 3D Stager in environments where it is not required (Adobe Advisory, CIS Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple Adobe product vulnerabilities disclosed in this patch cycle could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Tenable flagged the vulnerability in its plugin pipeline, and several security aggregators including RedPacket Security and CVEFeed.io published alerts shortly after disclosure. No significant independent researcher commentary or social media discussion beyond routine CVE tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."