Memory Corruption Vulnerability in Autodesk 3ds Max
CVE-2026-7454

7.8HIGH

Key Information:

Vendor

Autodesk

Status
Vendor
CVE Published:
26 May 2026

What is CVE-2026-7454?

A vulnerability exists in Autodesk 3ds Max due to improper handling of maliciously crafted WRL files. When these files are parsed by the application, they can lead to memory corruption, allowing an attacker to execute arbitrary code within the context of the running process. This issue underscores the importance of safeguarding against untrusted file formats, as exploitation can lead to compromise of system integrity.

Affected Version(s)

3ds Max 2027 < 2027.1

3ds Max 2026 < 2026.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.