AutoDesk
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any AutoDesk product.
RSS Feeds for AutoDesk security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in AutoDesk products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by AutoDesk Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 34 vulnerabilities in AutoDesk with an average score of 7.4 out of ten. Last year, in 2025 AutoDesk had 71 security vulnerabilities published. Right now, AutoDesk is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.36
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 34 | 7.43 |
| 2025 | 71 | 7.80 |
| 2024 | 102 | 7.70 |
| 2023 | 31 | 7.86 |
| 2022 | 73 | 7.81 |
| 2021 | 25 | 7.54 |
| 2020 | 7 | 0.00 |
| 2019 | 9 | 7.80 |
It may take a day or so for new AutoDesk vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent AutoDesk Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-14479 | Aug 12, 2026 |
Autodesk Installer IPC Parser Out-of-Range Substring DoSA maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition. |
|
| CVE-2026-14478 | Aug 12, 2026 |
Local Privileged IPC Injection via Named Pipes in Autodesk SoftwareA maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability. |
|
| CVE-2026-7406 | Aug 06, 2026 |
Autodesk BMP Untrusted Pointer Dereference (CVE-2026-7406)A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
And others... |
| CVE-2026-7405 | Aug 06, 2026 |
Autodesk Image Import OOB Read via Malicious TIFA maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service |
And others... |
| CVE-2026-11803 | Aug 06, 2026 |
Autodesk Revit OOB Read via Malicious PDF (CVE-2026-11803)A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
|
| CVE-2026-8325 | Aug 06, 2026 |
Autodesk Revit PDF OOBW VulnerabilityA maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2026-1289 | Aug 06, 2026 |
Autodesk Revit PDF Parser UAF Can Enable ExecA maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. |
|
| CVE-2026-10710 | Aug 04, 2026 |
Autodesk FBX SDK Buffer Overflow (ExtractDrive)A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2026-10709 | Aug 04, 2026 |
Autodesk FBX SDK stack buffer overflow via malicious FBX fileA maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2026-17550 | Jul 29, 2026 |
AutoCAD OOB Read via Malicious DWG/DXFA maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. |
And others... |
| CVE-2026-16465 | Jul 29, 2026 |
AutoCAD OOB Read in DWG/DXF ParserA maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. |
And others... |
| CVE-2026-16463 | Jul 29, 2026 |
AutoCAD DXF Heap OverflowA maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
And others... |
| CVE-2026-10789 | Jun 22, 2026 |
Autodesk Fusion Desktop MCP Extension Arbitrary Code Exec via Malicious WebpageA maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user. |
|
| CVE-2026-1288 | Jun 17, 2026 |
Autodesk Revit RFA-to-FormIt NPE DoS via Malicious RFAA maliciously crafted RFA file, when converted to FormIt via Convert RFA to FormIt in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition. |
|
| CVE-2026-7454 | May 26, 2026 |
Autodesk 3ds Max WRL File Memory Corruption CVE-2026-7454A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2026-7453 | May 26, 2026 |
3ds Max Stack Exhaustion via Malicious WRL FileA maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition. |
|
| CVE-2026-7452 | May 26, 2026 |
Autodesk 3ds Max WRL Memory Corruption CVE-2026-7452A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2026-7451 | May 26, 2026 |
Autodesk 3ds Max TIF OOBW VulnerabilityA maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2026-7450 | May 26, 2026 |
Autodesk 3ds Max PAR File NULL Pointer Deref DoSA maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition. |
|
| CVE-2026-4344 | Apr 14, 2026 |
Autodesk Fusion Stored XSS in Delete Confirm DialogA maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. |
|
| CVE-2026-4345 | Apr 14, 2026 |
Stored XSS via Malicious Design Name Export in Autodesk FusionA maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. |
|
| CVE-2026-4369 | Apr 14, 2026 |
Stored XSS in Fusion 360 via crafted HTML in assembly namesA maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. |
|
| CVE-2026-0875 | Feb 18, 2026 |
OOB Write via Malicious Autodesk MODEL FileA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2026-0874 | Feb 18, 2026 |
Out-of-Bounds Write in Autodesk Inventor via Malicious CATPART FileA maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2026-0536 | Feb 04, 2026 |
Stack Overflow via Malicious GIF in Autodesk 3ds MaxA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2026-0662 | Feb 04, 2026 |
Untrusted Search Path in Autodesk 3ds Max triggers arbitrary code execA maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized. |
|
| CVE-2026-0660 | Feb 04, 2026 |
Autodesk 3ds Max GIF Stack Buffer Overflow CVE-2026-0660A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2026-0661 | Feb 04, 2026 |
Memory Corruption in Autodesk 3ds Max via RGB FileA maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2026-0537 | Feb 04, 2026 |
Autodesk 3ds Max RGB Parser Memory Corruption Code ExecutionA maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2026-0538 | Feb 04, 2026 |
Autodesk 3ds Max GIF OOB Write Enables Arbitrary Code ExecA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2026-0659 | Feb 04, 2026 |
Autodesk Arnold/3ds Max OOB Write via Malicious USDA maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
And others... |
| CVE-2026-0535 | Jan 22, 2026 |
Autodesk Fusion Desktop Stored XSS via Component DescriptionA maliciously crafted HTML payload, stored in a components description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. |
|
| CVE-2026-0534 | Jan 22, 2026 |
Autodesk Fusion Desktop XSS via parts attributeA maliciously crafted HTML payload, stored in a parts attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. |
|
| CVE-2026-0533 | Jan 22, 2026 |
Autodesk Fusion Stored XSS via malicious HTML payload in design nameA maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. |
|
| CVE-2025-10900 | Dec 15, 2025 |
Autodesk MODEL File OOB Write via Crafted ParsingAA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-10899 | Dec 15, 2025 |
Autodesk 3ds Max OOB Write via malicious MODEL fileAA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-10898 | Dec 15, 2025 |
Autodesk OOBW via crafted MODEL fileAA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-10889 | Dec 15, 2025 |
Autodesk CAD CATPART MEMCORR CVE-2025-10889A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2025-10888 | Dec 15, 2025 |
Autodesk Model Parser OOB Write via Malicious MODEL File (CVE-2025-10888)AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-10887 | Dec 15, 2025 |
Autodesk Model File Memory Corruption Arbitrary Code ExecA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2025-10886 | Dec 15, 2025 |
Autodesk Model File Parsing Causing Memory Corruption Code ExecutionA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2025-10884 | Dec 15, 2025 |
Autodesk Inventor OOB Write via Malicious CATPARTAA maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-10883 | Dec 15, 2025 |
Autodesk CATPRODUCT OOB Read via Malicious FileA maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-10882 | Dec 15, 2025 |
Autodesk Products OOB Write via Malicious X_T FileAA maliciously crafted X_T file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-10881 | Dec 15, 2025 |
Autodesk Inventor Heap Overflow via CATPRODUCT fileA maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-9460 | Dec 15, 2025 |
Autodesk OOB Read in SLDPRT ParsingA maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-9459 | Dec 15, 2025 |
Autodesk OOB Read via malicious SLDPRT fileA maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
|
| CVE-2025-9457 | Dec 15, 2025 |
Autodesk PRT Memory Corruption Vulnerability CVE-2025-9457A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2025-9456 | Dec 15, 2025 |
Autodesk Inventor: SLDPRT Memory Corruption Enables Remote Code ExecutionA maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
|
| CVE-2025-9455 | Dec 15, 2025 |
Autodesk CAD OOB Read via CATPRODUCT fileA maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
|