PatchSiren cyber security CVE debrief
CVE-2026-7452 Autodesk CVE debrief
A memory corruption vulnerability exists in Autodesk 3ds Max when parsing maliciously crafted WRL (VRML) files. The flaw, published 2026-05-26, allows arbitrary code execution in the context of the current process through local attack vectors requiring user interaction. The vulnerability affects 3ds Max versions 2026 and 2027. Autodesk has issued security advisory ADSK-SA-2026-0006 addressing this issue. The CVSS 3.1 score of 7.8 (HIGH) reflects significant confidentiality, integrity, and availability impacts, though exploitation requires local access and user interaction to open a malicious file.
- Vendor
- Autodesk
- Product
- 3ds Max
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-07-23
Who should care
Organizations using Autodesk 3ds Max 2026 or 2027 for 3D modeling and visualization, particularly those accepting WRL/VRML files from external sources. Security teams should prioritize patching due to the HIGH severity rating and potential for complete system compromise through user-targeted attacks.
Technical summary
The vulnerability stems from improper handling of WRL (VRML) file parsing in Autodesk 3ds Max, leading to memory corruption exploitable for arbitrary code execution. The attack requires local access and user interaction (opening a malicious file), with execution occurring in the context of the current 3ds Max process. Affected versions include 3ds Max 2026 and 2027. The underlying weakness is categorized as CWE-120 (Classic Buffer Overflow). No known exploitation in the wild has been reported, and the vulnerability is not listed in CISA KEV.
Defensive priority
HIGH
Recommended defensive actions
- Apply security updates from Autodesk as specified in vendor advisory ADSK-SA-2026-0006
- Restrict 3ds Max file opening to trusted WRL sources only
- Implement application whitelisting to prevent execution of untrusted 3ds Max instances
- Consider disabling WRL import functionality if not required for business operations
- Monitor for suspicious 3ds Max process behavior or unexpected child processes
- Train users to recognize and avoid opening unsolicited or unexpected 3ds Max files
Evidence notes
CVE published 2026-05-26T18:16:55.900Z; modified 2026-05-26T20:41:09.723Z. Affects 3ds Max 2026 and 2027 per NVD CPE data. Vendor advisory confirms issue. CWE-120 (Classic Buffer Overflow) identified as root cause weakness.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-7452 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-7452
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-7452 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7452
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.autodesk.com/products/autodesk-access/overview
[email protected] - Product
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0006
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.