VulnSea

autodesk has 10 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 7. The median CVSS is 7.8 (high). None have a confirmed exploitation report. Most affected products: revit (3), advance_steel (2), installer (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
8 prev 0

Products

  • revit 3
  • advance_steel 2
  • installer 2
  • shared_components 2
  • Fusion 1
10
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

autodesk vulnerabilities

CVEs affecting autodesk, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-85217High· 8.6
1w ago

Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated…

TwilightAutodesk · FusionEPSS 0.14%via CVEORG
CVE-2026-14479Medium· 5.5
1mo ago

A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation

A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may lev…

Sunlitautodesk · installerEPSS 0.11%via NVD
CVE-2026-14478High· 7.8
1mo ago

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact conf…

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact conf…

Twilightautodesk · installerEPSS 0.11%via NVD
CVE-2026-7405Medium· 5.5
1mo ago

A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library

A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service

Sunlitautodesk · advance_steelEPSS 0.11%via NVD
CVE-2026-7406High· 7.8
1mo ago

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the cur…

Twilightautodesk · advance_steelEPSS 0.13%via NVD
CVE-2026-8325High· 7.8
1mo ago

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary…

Twilightautodesk · revitEPSS 0.13%via NVD
CVE-2026-1289High· 7.8
1mo ago

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary co…

Twilightautodesk · revitEPSS 0.14%via NVD
CVE-2026-11803High· 7.8
1mo ago

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary co…

Twilightautodesk · revitEPSS 0.14%via NVD
CVE-2025-10898High· 7.8
9mo ago

AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability

AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbit…

Twilightautodesk · shared_componentsEPSS 0.26%via NVD
CVE-2025-10881High· 7.8
9mo ago

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbi…

Twilightautodesk · shared_componentsEPSS 0.28%via NVD
autodesk vulnerabilities (CVEs) · VulnSea