ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-16782
+4 in the same advisory: …19568 …16783 …7455 …16781
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability.

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

NVD description · AI analysis pending
7.8
group max
<1%
  • autodesk 3ds max
CVE-2026-14478
+1 in the same advisory: …14479
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into n

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.

NVD description · AI analysis pending
7.8
group max
<1%
  • autodesk installer
CVE-2026-1289
+2 in the same advisory: …11803 …8325
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability.

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.

NVD description · AI analysis pending
7.8<1%
  • autodesk revit
CVE-2026-7406
+1 in the same advisory: …7405
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability.

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

NVD description · AI analysis pending
7.8
group max
<1%
  • autodesk advance steel
  • autodesk autocad
  • autodesk autocad architecture
  • +1 more
CVE-2026-10710
+1 in the same advisory: …10709
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive.

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

NVD description · AI analysis pending
7.8<1%
  • autodesk fbx software development kit
CVE-2026-16463
+2 in the same advisory: …16465 …17550
A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability.

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

NVD description · AI analysis pending
7.8
group max
<1%
  • autodesk advance steel
  • autodesk autocad
  • autodesk autocad architecture
  • +1 more
CVE-2026-10789
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.

NVD description · AI analysis pending
9.6<1%
  • autodesk fusion