Vulnerability
Published 2026-09-17
Verified 2026-09-19

Affinity by Canva stack buffer overflow CVE-2026-81546 (CVSS 7.7 High); fix 3.3.0

CVE-2026-81546 (published ~17 September 2026 per Tenable/NVD indexing) covers a stack-based buffer overflow in the Affinity by Canva application before the 3.3.0 September 2026 release: inadequate bounds checking when parsing Affinity document files. A crafted Affinity document opened by a user can lead to arbitrary code execution. Tenable lists CVSS 3.1 base score 7.7 (High). Australia relevance: Affinity is Canva’s creative suite (Canva is Australian-headquartered). Patch: upgrade Affinity by Canva to 3.3.0 or later. No public exploitation claim on the Tenable/NVD snippets reviewed this pass. Primary: CVE/NVD/Tenable record; treat vendor release notes as authoritative for build numbers when published.

Product
Affinity by Canva (desktop creative suite)
Versions
Affected: before 3.3.0 (September 2026 release); fixed: 3.3.0+
CVSS
7.7
Exploited in Australia?
unknown
Patch to
Upgrade Affinity by Canva to 3.3.0 or later; treat untrusted .af* / Affinity documents as untrusted code until patched.

Primary: Tenable — CVE-2026-81546 Affinity by Canva (indexed 17 Sep 2026) · CVE: CVE-2026-81546 · NVD — CVE-2026-81546

vulnerabilities australia