CVE-2026-7405Medium· 5.5▾ SunlitA maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
advance_steel >= 2027, < 2027.1autocad >= 2027, < 2027.1autocad_architecture >= 2027, < 2027.1autocad_electrical >= 2027, < 2027.1autocad_lt >= 2027, < 2027.1autocad_map_3d >= 2027, < 2027.1autocad_mechanical >= 2027, < 2027.1autocad_mep >= 2027, < 2027.1autocad_plant_3d >= 2027, < 2027.1civil_3d >= 2027, < 2027.1dwg_trueview >= 2027, < 2027.1revit >= 2025, < 2025.3.5revit >= 2026, < 2026.5revit >= 2027, < 2027.1Upgrade past the affected range:
advance_steel 2027.1autocad 2027.1autocad_architecture 2027.1autocad_electrical 2027.1autocad_lt 2027.1autocad_map_3d 2027.1autocad_mechanical 2027.1autocad_mep 2027.1autocad_plant_3d 2027.1civil_3d 2027.1dwg_trueview 2027.1revit 2027.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-7406High· 7.8A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability
CVE-2026-11803High· 7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability
CVE-2026-8325High· 7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability
CVE-2026-1289High· 7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability
CVE-2025-10898High· 7.8AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability
CVE-2025-10881High· 7.8A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability