AutoDesk AutoDesk

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any AutoDesk product.

RSS Feeds for AutoDesk security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in AutoDesk products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by AutoDesk Sorted by Most Security Vulnerabilities since 2018

AutoDesk Autocad172 vulnerabilities

AutoDesk Autocad Plant 3d159 vulnerabilities

AutoDesk Autocad Mep159 vulnerabilities

AutoDesk Autocad Mechanical159 vulnerabilities

AutoDesk Autocad Architecture159 vulnerabilities

AutoDesk Autocad Electrical159 vulnerabilities

AutoDesk Autocad Map 3d137 vulnerabilities

AutoDesk Advance Steel97 vulnerabilities

AutoDesk Civil 3d96 vulnerabilities

AutoDesk Autocad Lt87 vulnerabilities

AutoDesk Autocad Civil 3d68 vulnerabilities

AutoDesk Autocad Advance Steel63 vulnerabilities

AutoDesk Navisworks47 vulnerabilities

AutoDesk Revit39 vulnerabilities

AutoDesk Shared Components32 vulnerabilities

AutoDesk Dwg Trueview26 vulnerabilities

AutoDesk 3ds Max25 vulnerabilities

AutoDesk Inventor20 vulnerabilities

AutoDesk Fusion13 vulnerabilities

AutoDesk Fbx Review9 vulnerabilities

AutoDesk Navisworks Manage6 vulnerabilities

AutoDesk Navisworks Simulate6 vulnerabilities

AutoDesk Autocad Mechnaical6 vulnerabilities

AutoDesk Installer6 vulnerabilities

AutoDesk Vred5 vulnerabilities

AutoDesk Navisworks Freedom4 vulnerabilities

AutoDesk Revit Lt4 vulnerabilities

AutoDesk Maya3 vulnerabilities

AutoDesk Realdwg2 vulnerabilities

AutoDesk Vault2 vulnerabilities

AutoDesk Fbx Sdk2 vulnerabilities

AutoDesk Arnold1 vulnerability

AutoDesk Usd For Arnold1 vulnerability

By the Year

In 2026 there have been 34 vulnerabilities in AutoDesk with an average score of 7.4 out of ten. Last year, in 2025 AutoDesk had 71 security vulnerabilities published. Right now, AutoDesk is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.36




Year Vulnerabilities Average Score
2026 34 7.43
2025 71 7.80
2024 102 7.70
2023 31 7.86
2022 73 7.81
2021 25 7.54
2020 7 0.00
2019 9 7.80

It may take a day or so for new AutoDesk vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent AutoDesk Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-14479 Aug 12, 2026
Autodesk Installer IPC Parser Out-of-Range Substring DoS A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition.
Installer
CVE-2026-14478 Aug 12, 2026
Local Privileged IPC Injection via Named Pipes in Autodesk Software A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.
Installer
CVE-2026-7406 Aug 06, 2026
Autodesk BMP Untrusted Pointer Dereference (CVE-2026-7406) A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Revit
Autocad
Autocad Lt
And others...
CVE-2026-7405 Aug 06, 2026
Autodesk Image Import OOB Read via Malicious TIF A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
Revit
Autocad
Autocad Lt
And others...
CVE-2026-11803 Aug 06, 2026
Autodesk Revit OOB Read via Malicious PDF (CVE-2026-11803) A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Revit
CVE-2026-8325 Aug 06, 2026
Autodesk Revit PDF OOBW Vulnerability A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Revit
CVE-2026-1289 Aug 06, 2026
Autodesk Revit PDF Parser UAF Can Enable Exec A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
Revit
CVE-2026-10710 Aug 04, 2026
Autodesk FBX SDK Buffer Overflow (ExtractDrive) A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Fbx Sdk
CVE-2026-10709 Aug 04, 2026
Autodesk FBX SDK stack buffer overflow via malicious FBX file A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Fbx Sdk
CVE-2026-17550 Jul 29, 2026
AutoCAD OOB Read via Malicious DWG/DXF A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
Autocad
Autocad Lt
Dwg Trueview
And others...
CVE-2026-16465 Jul 29, 2026
AutoCAD OOB Read in DWG/DXF Parser A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
Autocad
Autocad Lt
Dwg Trueview
And others...
CVE-2026-16463 Jul 29, 2026
AutoCAD DXF Heap Overflow A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Autocad
Autocad Lt
Dwg Trueview
And others...
CVE-2026-10789 Jun 22, 2026
Autodesk Fusion Desktop MCP Extension Arbitrary Code Exec via Malicious Webpage A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.
Fusion
CVE-2026-1288 Jun 17, 2026
Autodesk Revit RFA-to-FormIt NPE DoS via Malicious RFA A maliciously crafted RFA file, when converted to FormIt via Convert RFA to FormIt in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.
Revit
CVE-2026-7454 May 26, 2026
Autodesk 3ds Max WRL File Memory Corruption CVE-2026-7454 A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
3ds Max
CVE-2026-7453 May 26, 2026
3ds Max Stack Exhaustion via Malicious WRL File A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.
3ds Max
CVE-2026-7452 May 26, 2026
Autodesk 3ds Max WRL Memory Corruption CVE-2026-7452 A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
3ds Max
CVE-2026-7451 May 26, 2026
Autodesk 3ds Max TIF OOBW Vulnerability A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
3ds Max
CVE-2026-7450 May 26, 2026
Autodesk 3ds Max PAR File NULL Pointer Deref DoS A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.
3ds Max
CVE-2026-4344 Apr 14, 2026
Autodesk Fusion Stored XSS in Delete Confirm Dialog A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Fusion
CVE-2026-4345 Apr 14, 2026
Stored XSS via Malicious Design Name Export in Autodesk Fusion A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Fusion
CVE-2026-4369 Apr 14, 2026
Stored XSS in Fusion 360 via crafted HTML in assembly names A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Fusion
CVE-2026-0875 Feb 18, 2026
OOB Write via Malicious Autodesk MODEL File A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Shared Components
CVE-2026-0874 Feb 18, 2026
Out-of-Bounds Write in Autodesk Inventor via Malicious CATPART File A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Shared Components
Inventor
CVE-2026-0536 Feb 04, 2026
Stack Overflow via Malicious GIF in Autodesk 3ds Max A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
3ds Max
CVE-2026-0662 Feb 04, 2026
Untrusted Search Path in Autodesk 3ds Max triggers arbitrary code exec A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
3ds Max
CVE-2026-0660 Feb 04, 2026
Autodesk 3ds Max GIF Stack Buffer Overflow CVE-2026-0660 A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
3ds Max
CVE-2026-0661 Feb 04, 2026
Memory Corruption in Autodesk 3ds Max via RGB File A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
3ds Max
CVE-2026-0537 Feb 04, 2026
Autodesk 3ds Max RGB Parser Memory Corruption Code Execution A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
3ds Max
CVE-2026-0538 Feb 04, 2026
Autodesk 3ds Max GIF OOB Write Enables Arbitrary Code Exec A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
3ds Max
CVE-2026-0659 Feb 04, 2026
Autodesk Arnold/3ds Max OOB Write via Malicious USD A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Usd For Arnold
Arnold
3ds Max
And others...
CVE-2026-0535 Jan 22, 2026
Autodesk Fusion Desktop Stored XSS via Component Description A maliciously crafted HTML payload, stored in a components description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Fusion
CVE-2026-0534 Jan 22, 2026
Autodesk Fusion Desktop XSS via parts attribute A maliciously crafted HTML payload, stored in a parts attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Fusion
CVE-2026-0533 Jan 22, 2026
Autodesk Fusion Stored XSS via malicious HTML payload in design name A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Fusion
CVE-2025-10900 Dec 15, 2025
Autodesk MODEL File OOB Write via Crafted Parsing AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-10899 Dec 15, 2025
Autodesk 3ds Max OOB Write via malicious MODEL file AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Shared Components
3ds Max
CVE-2025-10898 Dec 15, 2025
Autodesk OOBW via crafted MODEL file AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-10889 Dec 15, 2025
Autodesk CAD CATPART MEMCORR CVE-2025-10889 A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-10888 Dec 15, 2025
Autodesk Model Parser OOB Write via Malicious MODEL File (CVE-2025-10888) AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-10887 Dec 15, 2025
Autodesk Model File Memory Corruption Arbitrary Code Exec A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-10886 Dec 15, 2025
Autodesk Model File Parsing Causing Memory Corruption Code Execution A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-10884 Dec 15, 2025
Autodesk Inventor OOB Write via Malicious CATPART AA maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Shared Components
Inventor
CVE-2025-10883 Dec 15, 2025
Autodesk CATPRODUCT OOB Read via Malicious File A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-10882 Dec 15, 2025
Autodesk Products OOB Write via Malicious X_T File AA maliciously crafted X_T file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-10881 Dec 15, 2025
Autodesk Inventor Heap Overflow via CATPRODUCT file A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-9460 Dec 15, 2025
Autodesk OOB Read in SLDPRT Parsing A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-9459 Dec 15, 2025
Autodesk OOB Read via malicious SLDPRT file A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-9457 Dec 15, 2025
Autodesk PRT Memory Corruption Vulnerability CVE-2025-9457 A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Shared Components
CVE-2025-9456 Dec 15, 2025
Autodesk Inventor: SLDPRT Memory Corruption Enables Remote Code Execution A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Shared Components
Inventor
CVE-2025-9455 Dec 15, 2025
Autodesk CAD OOB Read via CATPRODUCT file A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Shared Components
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.