PatchSiren cyber security CVE debrief
CVE-2026-7452 Autodesk CVE debrief
A memory corruption vulnerability exists in Autodesk 3ds Max when parsing maliciously crafted WRL (VRML) files. The flaw, published 2026-05-26, allows arbitrary code execution in the context of the current process through local attack vectors requiring user interaction. The vulnerability affects 3ds Max versions 2026 and 2027. Autodesk has issued security advisory ADSK-SA-2026-0006 addressing this issue. The CVSS 3.1 score of 7.8 (HIGH) reflects significant confidentiality, integrity, and availability impacts, though exploitation requires local access and user interaction to open a malicious file.
- Vendor
- Autodesk
- Product
- 3ds Max
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
Organizations using Autodesk 3ds Max 2026 or 2027 for 3D modeling and visualization, particularly those accepting WRL/VRML files from external sources. Security teams should prioritize patching due to the HIGH severity rating and potential for complete system compromise through user-targeted attacks.
Technical summary
The vulnerability stems from improper handling of WRL (VRML) file parsing in Autodesk 3ds Max, leading to memory corruption exploitable for arbitrary code execution. The attack requires local access and user interaction (opening a malicious file), with execution occurring in the context of the current 3ds Max process. Affected versions include 3ds Max 2026 and 2027. The underlying weakness is categorized as CWE-120 (Classic Buffer Overflow). No known exploitation in the wild has been reported, and the vulnerability is not listed in CISA KEV.
Defensive priority
HIGH
Recommended defensive actions
- Apply security updates from Autodesk as specified in vendor advisory ADSK-SA-2026-0006
- Restrict 3ds Max file opening to trusted WRL sources only
- Implement application whitelisting to prevent execution of untrusted 3ds Max instances
- Consider disabling WRL import functionality if not required for business operations
- Monitor for suspicious 3ds Max process behavior or unexpected child processes
- Train users to recognize and avoid opening unsolicited or unexpected 3ds Max files
Evidence notes
CVE published 2026-05-26T18:16:55.900Z; modified 2026-05-26T20:41:09.723Z. Affects 3ds Max 2026 and 2027 per NVD CPE data. Vendor advisory confirms issue. CWE-120 (Classic Buffer Overflow) identified as root cause weakness.
Official resources
-
CVE-2026-7452 CVE record
CVE.org
-
CVE-2026-7452 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Product
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
2026-05-26