Skip to content
AutodeskCVE-2026-16782

Autodesk 3ds Max: out-of-bounds read

Medium5.3CVE-2026-16782 · Published Aug 24, 2026 · updated Aug 28, 2026

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Autodesk advisory

Affected versions

PackageAffectedFixed in
3ds Max
Product
>= 2027.0.0, < 2027.2.02027.2.0
>= 2026.0.0, < 2026.3.42026.3.4
Details and references

More Autodesk advisories

All Autodesk
Advisory
Autodesk Shared Components: denial of service
Medium5.5Sep 2
Autodesk 3ds Max: out-of-bounds write
High7.8Aug 24
Autodesk 3ds Max: out-of-bounds write
High7.8Aug 24
Autodesk 3ds Max: memory corruption
High7.8Aug 24
Autodesk 3ds Max: denial of service
Medium5.5Aug 24
Autodesk Installer: insecure permissions
High7.8Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.