Heap-based buffer overflow in Autodesk products - CVE-2026-16463
Published: July 29, 2026 / Updated: July 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the DXF file parser when parsing a crafted DXF file. A remote attacker can supply a specially crafted file to execute arbitrary code.
User interaction is required to open or parse the crafted file.
Affected software
AutoCAD Architecture
AutoCAD Electrical
AutoCAD Mechanical
AutoCAD MEP
AutoCAD Plant 3D
Autodesk Civil 3D
Advance Steel
AutoCAD Map 3D
AutoCAD LT
DWG Trueview
How to mitigate CVE-2026-16463
AutoCAD Architecture - update to 2027.1
AutoCAD Electrical - update to 2027.1
AutoCAD Mechanical - update to 2027.1
AutoCAD MEP - update to 2027.1
AutoCAD Plant 3D - update to 2027.1
Autodesk Civil 3D - update to 2027.1
Advance Steel - update to 2027.1
AutoCAD Map 3D - update to 2027.1
AutoCAD LT - update to 2027.1
DWG Trueview - update to 2027.1