NULL pointer dereference in Revit - CVE-2026-1288
Published: June 17, 2026
Revit
Detailed vulnerability description
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to null pointer dereference in the RFA file conversion feature when converting a crafted RFA file to FormIt via "Convert RFA to FormIt". A remote attacker can supply a maliciously crafted RFA file to cause a denial of service.
User interaction is required to open and convert the crafted file.