PatchSiren

Adobe CVE debriefs · Page 14

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Adobe CVE published 2026-03-10

CVE-2026-27219

Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has been publicly disclosed and requires immediate attent [truncated]

MEDIUM Adobe CVE published 2026-03-10

CVE-2026-27218

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

MEDIUM Adobe CVE published 2026-03-10

CVE-2026-27217

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to its availability. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

MEDIUM Adobe CVE published 2026-03-10

CVE-2026-27216

Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has the potential to expose sensitive information, emphas [truncated]

MEDIUM Adobe CVE published 2026-03-10

CVE-2026-27215

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to its availability. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

MEDIUM Adobe CVE published 2026-03-10

CVE-2026-21364

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

MEDIUM Adobe CVE published 2026-03-10

CVE-2026-21363

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

MEDIUM Adobe CVE published 2026-02-10

CVE-2026-21348

Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. This vulnerability, classified as an out-of-bounds read issue, can be triggered by processing a specially crafted file, potentially disclosing sensitive information stored in memory. Exploitation requires user interaction, as a victim must open a malicious file. The CVE [truncated]

MEDIUM Adobe CVE published 2026-02-10

CVE-2026-21354

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-10T19:15:59.140Z and has not been modified since then. The CVE-2026-21354 vulnerability is an Integer Overflow or Wraparound issue in DNG SDK versions 1.7.1 2410 and earlier. This vulnerability could lead to application denial-of-service if a victim opens a malicious file. The vulnerability has a CV [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21353

PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-10T19:15:58.373Z and has not been modified since then. The vulnerability affects DNG SDK versions 1.7.1 2410 and earlier, and it is an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21345

Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file. This could result in a read past the end of an allocated memory structure, potentially allowing an attacker to execute code in the context of the current user if a victim opens a malicious file. The vulnerability requires user interaction and is triggered when a victim opens a m [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21344

Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file. This vulnerability could result in a read past the end of an allocated memory structure, potentially allowing an attacker to execute code in the context of the current user if a victim opens a malicious file. The vulnerability is caused by an out-of-bounds read when parsing a cr [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21343

Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file. This could result in a read past the end of an allocated memory structure, potentially allowing an attacker to execute code in the context of the current user if a victim opens a malicious file. The vulnerability requires user interaction and can be triggered by opening a specia [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21342

Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability, a type of issue that can lead to arbitrary code execution in the context of the current user. This vulnerability requires user interaction, as a victim must open a malicious file. The affected product, Substance3D - Stager, is used for 3D rendering and design. The vulnerability has a high CVSS score of 7. [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21341

Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has a high CVSS score of 7.8, indicating a high severity level. The affected product, Substance3D - Stager, [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21351

The CVE-2026-21351 vulnerability is a Use After Free issue affecting Adobe After Effects versions 25.6 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The issue has a CVSS score of 7.8 and is classified as HIGH severity. Users of Adobe After Effects versions 25.6 and earlier, IT administrators [truncated]

MEDIUM Adobe CVE published 2026-02-10

CVE-2026-21350

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-10T18:16:32.403Z and has not been modified since then. CVE-2026-21350 is a NULL Pointer Dereference vulnerability affecting Adobe After Effects versions 25.6 and earlier, which could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing [truncated]

MEDIUM Adobe CVE published 2026-02-10

CVE-2026-21332

CVE-2026-21332 is an out-of-bounds read vulnerability in Adobe InDesign versions 21.1, 20.5.1, and earlier. This vulnerability could lead to memory exposure if a victim opens a malicious file. User interaction is required for exploitation. The vulnerability was published on 2026-02-10T18:16:31.147Z and has not been modified since then. Affected users should apply patches or updates to prevent potential me [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21330

The CVE-2026-21330 vulnerability is a Type Confusion issue affecting Adobe After Effects versions 25.6 and earlier. It allows for arbitrary code execution in the context of the current user when a malicious file is opened. This vulnerability requires user interaction and has a CVSS score of 7.8. Administrators and users of Adobe After Effects versions 25.6 and earlier should apply patches or updates to pr [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21329

CVE-2026-21329 is a Use After Free vulnerability in Adobe After Effects versions 25.6 and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. This type of vulnerability typically involves memory corruption and can lead to code execution if exploited. Affected systems include those running Adobe After E [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21328

CVE-2026-21328 is an out-of-bounds write vulnerability in Adobe After Effects versions 25.6 and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. This issue is a high-severity vulnerability that requires immediate attention. Organizations and individuals using Adobe After Effects versions 25.6 or ear [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21326

The CVE-2026-21326 vulnerability is a Use After Free issue in Adobe After Effects versions 25.6 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVE record was published on 2026-02-10T18:16:30.380Z and has not been modified since then. Administrators and users of Adobe After Effects version [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21324

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-10T18:16:30.080Z and has not been modified since then. CVE-2026-21324 is an out-of-bounds read vulnerability in Adobe After Effects versions 25.6 and earlier. The vulnerability can result in code execution in the context of the current user when a crafted file is opened. This issue requires user int [truncated]

HIGH Adobe CVE published 2026-02-10

CVE-2026-21322

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-10T18:16:29.770Z and has not been modified since then. The CVE-2026-21322 vulnerability is an out-of-bounds read issue in Adobe After Effects versions 25.6 and earlier. When parsing a crafted file, the application may read past the end of an allocated memory structure. This could potentially allow a [truncated]

MEDIUM Adobe CVE published 2026-02-10

CVE-2026-21319

Adobe After Effects versions 25.6 and earlier contain an Out-of-bounds Read vulnerability. This vulnerability could lead to memory exposure if a victim opens a malicious file, requiring user interaction. The issue is an Out-of-bounds Read problem that could allow attackers to access sensitive information stored in memory. Users should be cautious when opening files from untrusted sources.

HIGH Adobe CVE published 2026-02-10

CVE-2026-21318

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-21318 was published on 2026-02-10T18:16:29.177Z. This CVE record details an out-of-bounds write vulnerability in Adobe After Effects versions 25.6 and earlier, which could result in arbitrary code execution in the context of the current user if a victim opens a malicious file. The CVSS score is 7.8, classified [truncated]

MEDIUM Adobe CVE published 2026-02-10

CVE-2026-21314

Adobe Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has been publicly disclosed and may be targeted. Users should pr [truncated]

MEDIUM Adobe CVE published 2026-02-10

CVE-2026-21313

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-10T18:16:28.417Z and has not been modified since then. CVE-2026-21313 is a medium-severity vulnerability classified as an out-of-bounds read issue in Adobe Audition versions 25.3 and earlier. This vulnerability could lead to memory exposure and potentially allow an attacker to disclose sensitive inf [truncated]

MEDIUM Adobe CVE published 2026-01-13

CVE-2026-21303

Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has been publicly disclosed and verified through variou [truncated]

MEDIUM Adobe CVE published 2026-01-13

CVE-2026-21301

Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability is confined to user interaction with malicious files, and there are no reports of in-the-wild exploitation. The issue is related to de [truncated]