Skip to content
AutodeskCVE-2026-85217

Autodesk Fusion: information disclosure

High8.6CVE-2026-85217 · Published Sep 10, 2026 · updated Sep 11, 2026

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.

Autodesk advisory

Affected versions

PackageAffectedFixed in
Fusion
Product
>= 2705.0.0, < 2705.1.112705.1.11
Details and references

More Autodesk advisories

All Autodesk
Advisory
Autodesk Shared Components: denial of service
Medium5.5Sep 2
Autodesk 3ds Max: out-of-bounds write
High7.8Aug 24
Autodesk 3ds Max: out-of-bounds write
High7.8Aug 24
Autodesk 3ds Max: memory corruption
High7.8Aug 24
Autodesk 3ds Max: denial of service
Medium5.5Aug 24
Autodesk 3ds Max: out-of-bounds read
Medium5.3Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.