[NEW] [medium] Adobe Creative Cloud (Substance 3D, XD, and Illustrator): Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in the Adobe Creative Cloud applications Substance 3D, XD, and Illustrator to execute arbitrary code, perform a denial of service attack, and disclose information.
CSIRTS triage
- What
- Multiple vulnerabilities in Adobe Creative Cloud applications enable remote code execution, denial of service, and information disclosure.
- Who is affected
- Users of Adobe Substance 3D, XD, and Illustrator are affected when opening untrusted files or projects.
- Urgency
- Medium priority; RCE in creative applications can compromise design systems and sensitive project data.
- Action
- Update Adobe Creative Cloud applications to the latest patched versions addressing CVE-2026-48417 through CVE-2026-48424.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Creative Cloud (Substance 3D, XD, Illustrator)
Get an email when a new Creative Cloud (Substance 3D, XD, Illustrator) advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3022
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-484170.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484180.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484190.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484200.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484210.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484220.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484230.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484240.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484250.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484260.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-75770: Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in…nvd
- highCVE-2026-75769: Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could res…nvd
- highCVE-2026-75768: Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result …nvd
- highCVE-2026-75767: Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could res…nvd
- highCVE-2026-75766: Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could res…nvd
- mediumCVE-2026-75752: Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to di…nvd
- highCVE-2026-75750: Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could res…nvd
- highCVE-2026-75749: Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in…nvd
- highCVE-2026-71564: Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result i…nvd
- mediumCVE-2026-71441: Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure o…nvd
- highCVE-2026-71399: Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code ex…nvd
- highCVE-2026-71382: Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in…nvd
Recent advisories for Adobe Creative Cloud
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEU] [hoch] Adobe Creative Cloud (Illustrator und Animate): Mehrere Schwachstellen ermöglichen Codeausführungcert-bund · 2026-09-09
- medium[UPDATE] [medium] Adobe Creative Cloud applications: Multiple vulnerabilitiescert-bund · 2026-08-28
- high[NEW] [high] Adobe Creative Cloud (Lightroom Classic): Multiple vulnerabilities enable Code Executioncert-bund · 2026-08-12
- high[NEW] [high] Adobe Creative Cloud (Bridge and Format Plugins): Multiple vulnerabilitiescert-bund · 2026-07-29
- high[NEW] [high] Adobe Creative Cloud Applications: Multiple vulnerabilitiescert-bund · 2026-07-15
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10