HIGH🇵🇱 Wersja polska

CVE-2026-16463

CVSS 7.8v3.1pub. 2026-07-29upd. 2026-09-02

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Autodesk Advance Steel

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Autocad

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Autocad Architecture

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Autocad Electrical

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Autocad Lt

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Autocad Map 3d

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Autocad Mechanical

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Autocad Mep

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Autocad Plant 3d

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Civil 3d

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
  • Autodesk Dwg Trueview

    APP
    Autodesk
    20272026 – 2026.1.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoS
CWE
References

Related vulnerabilities

CVE-2023-29076CRITICAL9.8PL ✓same product

Autodesk AutoCAD — uszkodzenie pamięci przy parsowaniu plików 3D (RCE)

CVE-2023-29073CRITICAL9.8PL ✓same product

Heap-Based Buffer Overflow w Autodesk AutoCAD przy parsowaniu pliku MODEL

CVE-2023-29074CRITICAL9.8PL ✓same product

Autodesk AutoCAD: Out-Of-Bounds Write przy parsowaniu pliku CATPART

CVE-2023-29075CRITICAL9.8PL ✓same product

Out-Of-Bounds Write w Autodesk AutoCAD przy parsowaniu pliku PRT

CVE-2026-7406HIGH7.8PL ✓same product

RCE poprzez złośliwy plik BMP w produktach Autodesk (Untrusted Pointer Dereference)