autodesk has 10 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 7. The median CVSS is 7.8 (high). None have a confirmed exploitation report. Most affected products: revit (3), advance_steel (2), installer (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 8 prev 0
Weakness classes
Products
- revit 3
- advance_steel 2
- installer 2
- shared_components 2
- Fusion 1
Worst active — by depth score
CVE-2026-85217High· 8.6Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop47CVE-2026-14478High· 7.8A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact conf…43CVE-2026-8325High· 7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability43CVE-2026-7406High· 7.8A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability43CVE-2026-1289High· 7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability43
autodesk vulnerabilities
CVEs affecting autodesk, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-85217High· 8.6Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop
A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated…
CVE-2026-14479Medium· 5.5A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation
A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may lev…
CVE-2026-14478High· 7.8A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact conf…
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact conf…
CVE-2026-7405Medium· 5.5A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
CVE-2026-7406High· 7.8A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the cur…
CVE-2026-8325High· 7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary…
CVE-2026-1289High· 7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary co…
CVE-2026-11803High· 7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary co…
CVE-2025-10898High· 7.8AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability
AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbit…
CVE-2025-10881High· 7.8A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability
A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbi…