Affinity by Canva stack buffer overflow CVE-2026-81546 (CVSS 7.7 High); fix 3.3.0
CVE-2026-81546 (published ~17 September 2026 per Tenable/NVD indexing) covers a stack-based buffer overflow in the Affinity by Canva application before the 3.3.0 September 2026 release: inadequate bounds checking when parsing Affinity document files. A crafted Affinity document opened by a user can lead to arbitrary code execution. Tenable lists CVSS 3.1 base score 7.7 (High). Australia relevance: Affinity is Canva’s creative suite (Canva is Australian-headquartered). Patch: upgrade Affinity by Canva to 3.3.0 or later. No public exploitation claim on the Tenable/NVD snippets reviewed this pass. Primary: CVE/NVD/Tenable record; treat vendor release notes as authoritative for build numbers when published.
- Product
- Affinity by Canva (desktop creative suite)
- Versions
- Affected: before 3.3.0 (September 2026 release); fixed: 3.3.0+
- CVSS
- 7.7
- Exploited in Australia?
- unknown
- Patch to
- Upgrade Affinity by Canva to 3.3.0 or later; treat untrusted .af* / Affinity documents as untrusted code until patched.
Primary: Tenable — CVE-2026-81546 Affinity by Canva (indexed 17 Sep 2026) · CVE: CVE-2026-81546 · NVD — CVE-2026-81546
