AdobeCVE-2026-83959
Adobe Substance 3D Sampler: heap buffer overflow
High7.8CVE-2026-83959 · Published Sep 3, 2026 · updated Sep 8, 2026
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Adobe Substance 3D Sampler Product | <= 6.0.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-122
More Adobe advisories
All Adobe| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Adobe Commerce: cross-site scripting | Critical9.3 | No fix yet |
| Sep 8 | Adobe Photoshop Android: path traversal | Medium5.0 | No fix yet |
| Sep 8 | Adobe Photoshop Android: session fixation | High7.4 | No fix yet |
| Sep 8 | Adobe Animate: code injection | High8.2 | No fix yet |
| Sep 7 | Adobe Commerce: code execution | Critical10.0 | No fix yet |
| Sep 3 | Adobe ColdFusion: improper authentication | High7.1 | No fix yet |