PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-21301 Adobe CVE debrief

Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability is confined to user interaction with malicious files, and there are no reports of in-the-wild exploitation. The issue is related to denial-of-service, and technical details are limited. Users should review and apply patches. IT administrators and security teams responsible for managing software updates and user interactions with potentially malicious files should prioritize this vulnerability.

Vendor
Adobe
Product
Substance3D - Modeler
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-13
Original CVE updated
2026-08-28
Advisory published
2026-01-13
Advisory updated
2026-08-28

Who should care

Users of Substance 3D Modeler versions 1.22.4 and earlier should review and apply patches. IT administrators and security teams responsible for managing software updates and user interactions with potentially malicious files should prioritize this vulnerability. Operators and platform administrators should assess affected deployments and ensure timely patching. Vulnerability management and security teams should monitor for suspicious file interactions and implement compensating controls if necessary. Asset owners should verify that their systems are updated and review access controls for untrusted file sources.

Technical summary

Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability. This vulnerability could lead to application denial-of-service and requires user interaction to exploit, as a victim must open a malicious file. The issue is confined to user interaction with malicious files, and there are no reports of in-the-wild exploitation. Technical details are limited, but the vulnerability's impact is related to denial-of-service.

Defensive priority

Medium-priority defensive review recommended due to potential for denial-of-service through malicious file interaction.

Recommended defensive actions

  • Review and apply vendor patches for Substance 3D Modeler
  • Restrict user access to untrusted file sources
  • Implement monitoring for suspicious file interactions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Official CVE Program record and NVD vulnerability detail page confirm NULL Pointer Dereference vulnerability in Substance 3D Modeler versions 1.22.4 and earlier. Vendor advisory from Adobe provides additional context. The vulnerability requires user interaction to exploit, as a victim must open a malicious file. There is no information on known or unknown affected scope beyond the specified versions. Defenders should verify patch application and monitor for suspicious file interactions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-21301 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-21301

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-21301 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21301

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.