彙總 Autodesk 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
已披露問題常與 緩衝區溢位、跨站腳本與路徑處理缺陷 相關,可能在 生產負載與軟體部署 場景中帶來 應用程式崩潰與工作階段劫持 等暴露風險。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2026-7454 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | [email protected] | 7.8 | 0.01% | 2026-05-26 | 2026-05-26 |
| CVE-2026-7453 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition. | [email protected] | 5.5 | 0.00% | 2026-05-26 | 2026-06-03 |
| CVE-2026-7452 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | [email protected] | 7.8 | 0.01% | 2026-05-26 | 2026-05-26 |
| CVE-2026-7451 | A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | [email protected] | 7.8 | 0.01% | 2026-05-26 | 2026-05-26 |
| CVE-2026-7450 | A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition. | [email protected] | 5.5 | 0.00% | 2026-05-26 | 2026-06-03 |
| CVE-2026-4369 | A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. | [email protected] | 7.1 | 0.02% | 2026-04-14 | 2026-04-22 |
| CVE-2026-4345 | A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. | [email protected] | 7.1 | 0.02% | 2026-04-14 | 2026-04-22 |
| CVE-2026-4344 | A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. | [email protected] | 7.1 | 0.02% | 2026-04-14 | 2026-04-22 |
| CVE-2026-0875 | A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | [email protected] | 7.8 | 0.01% | 2026-02-18 | 2026-02-20 |
| CVE-2026-0874 | A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | [email protected] | 7.8 | 0.01% | 2026-02-18 | 2026-02-20 |
| CVE-2026-0536 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | [email protected] | 7.8 | 0.01% | 2026-02-04 | 2026-02-05 |
| CVE-2026-0662 | A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized. | [email protected] | 7.8 | 0.01% | 2026-02-04 | 2026-02-06 |
| CVE-2026-0661 | A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | [email protected] | 8.4 | 0.01% | 2026-02-04 | 2026-06-03 |
| CVE-2026-0660 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | [email protected] | 8.4 | 0.01% | 2026-02-04 | 2026-06-03 |
| CVE-2026-0538 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | [email protected] | 8.4 | 0.01% | 2026-02-04 | 2026-06-03 |
| CVE-2026-0537 | A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | [email protected] | 8.4 | 0.01% | 2026-02-04 | 2026-06-03 |
| CVE-2026-0535 | A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. | [email protected] | 8.1 | 0.01% | 2026-01-22 | 2026-06-03 |
| CVE-2026-0534 | A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. | [email protected] | 8.1 | 0.02% | 2026-01-22 | 2026-06-03 |
| CVE-2026-0533 | A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process. | [email protected] | 8.1 | 0.02% | 2026-01-22 | 2026-06-03 |
| CVE-2025-9460 | A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | [email protected] | 7.8 | 0.01% | 2025-12-16 | 2025-12-19 |