Heap-based buffer overflow in Autodesk products - CVE-2026-16463

 

Heap-based buffer overflow in Autodesk products - CVE-2026-16463

Published: July 29, 2026 / Updated: July 30, 2026


Vulnerability identifier: #VU140566
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-16463
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Autodesk AutoCAD
AutoCAD Architecture
AutoCAD Electrical
AutoCAD Mechanical
AutoCAD MEP
AutoCAD Plant 3D
Autodesk Civil 3D
Advance Steel
AutoCAD Map 3D
AutoCAD LT
DWG Trueview

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in the DXF file parser when parsing a crafted DXF file. A remote attacker can supply a specially crafted file to execute arbitrary code.

User interaction is required to open or parse the crafted file.


How to mitigate CVE-2026-16463

Install security update from vendor's website.

Sources