← Vulnerability feed

Vulnerability record · CVE-2026-0661 · published 4 February 2026

CVE-2026-0661: Autodesk 3ds max out-of-bounds write vulnerability

Autodesk · 3ds Max

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

8.4 CVSS 3.1 High EPSS 0.18% · top 93.0% CWE-787 · Out-of-bounds write
8.4CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-0661 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-3577Autodesk 3ds max code injection vulnerabilityAutodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript …EPSS 5.1%8.4CVE-2026-0537Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.18%8.4CVE-2026-0538Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage …EPSS 0.18%8.4CVE-2026-0660Autodesk 3ds max stack-based buffer overflow vulnerabilityA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can le…EPSS 0.20%7.8CVE-2026-7455Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …EPSS 0.19%7.8CVE-2026-16783Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …EPSS 0.13%7.8CVE-2026-19568Autodesk 3ds max classic buffer overflow vulnerabilityA maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.13%7.8CVE-2026-16782Autodesk 3ds max out-of-bounds read vulnerabilityA maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage t…EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2026-0661), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.