PatchSiren cyber security CVE debrief
CVE-2026-21301 Adobe CVE debrief
Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability is confined to user interaction with malicious files, and there are no reports of in-the-wild exploitation. The issue is related to denial-of-service, and technical details are limited. Users should review and apply patches. IT administrators and security teams responsible for managing software updates and user interactions with potentially malicious files should prioritize this vulnerability.
- Vendor
- Adobe
- Product
- Substance3D - Modeler
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-13
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-01-13
- Advisory updated
- 2026-08-28
Who should care
Users of Substance 3D Modeler versions 1.22.4 and earlier should review and apply patches. IT administrators and security teams responsible for managing software updates and user interactions with potentially malicious files should prioritize this vulnerability. Operators and platform administrators should assess affected deployments and ensure timely patching. Vulnerability management and security teams should monitor for suspicious file interactions and implement compensating controls if necessary. Asset owners should verify that their systems are updated and review access controls for untrusted file sources.
Technical summary
Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability. This vulnerability could lead to application denial-of-service and requires user interaction to exploit, as a victim must open a malicious file. The issue is confined to user interaction with malicious files, and there are no reports of in-the-wild exploitation. Technical details are limited, but the vulnerability's impact is related to denial-of-service.
Defensive priority
Medium-priority defensive review recommended due to potential for denial-of-service through malicious file interaction.
Recommended defensive actions
- Review and apply vendor patches for Substance 3D Modeler
- Restrict user access to untrusted file sources
- Implement monitoring for suspicious file interactions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Official CVE Program record and NVD vulnerability detail page confirm NULL Pointer Dereference vulnerability in Substance 3D Modeler versions 1.22.4 and earlier. Vendor advisory from Adobe provides additional context. The vulnerability requires user interaction to exploit, as a victim must open a malicious file. There is no information on known or unknown affected scope beyond the specified versions. Defenders should verify patch application and monitor for suspicious file interactions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-21301 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-21301
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-21301 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21301
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-08.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.