CVE-2026-21287: Substance3D - Stager | Use After Free (CWE-416)
Published Jan 13, 2026
·Updated
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Substance3D Stager<=3.1.5
All of the following
Adobe Substance 3D Stager<3.1.6
Any of the following
Apple macOS
Microsoft Windows
Event History
Jan 13, 2026
CVE Published
via MITRE·07:44 PM
Data Sourced
via MITRE·07:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Jan 6, 58022
Event
via FIRST·07:21 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-21287?
CVE-2026-21287 is considered a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2026-21287?
To fix CVE-2026-21287, update Substance3D - Stager to version 3.1.6 or later.
3
Who is affected by CVE-2026-21287?
CVE-2026-21287 affects users of Substance3D - Stager versions 3.1.5 and earlier.
4
What type of vulnerability is CVE-2026-21287?
CVE-2026-21287 is a Use After Free vulnerability, categorized under CWE-416.
5
What are the consequences of CVE-2026-21287 exploitation?
Exploitation of CVE-2026-21287 could result in arbitrary code execution in the context of the current user.