← Vulnerability feed

Vulnerability record · CVE-2026-7406 · published 6 August 2026

CVE-2026-7406: Autodesk advance steel vulnerability

Autodesk · Advance Steel

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

7.8 CVSS 3.1 High EPSS 0.19% · top 91.9% CWE-822 · CWE-822
7.8CVSS 3.1 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
2References
18 Sep 2026Last modified by NVD

Description

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7406 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29074Autodesk autocad out-of-bounds write vulnerabilityA maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor …EPSS 1.1%9.8CVE-2023-29075Autodesk autocad out-of-bounds write vulnerabilityA maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can …EPSS 1.1%9.8CVE-2023-29076Autodesk autocad memory buffer overflow vulnerabilityA maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerabili…EPSS 1.1%9.8CVE-2023-29073Autodesk autocad heap-based buffer overflow vulnerabilityA maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious ac…EPSS 1.1%7.8CVE-2026-16463Autodesk advance steel heap-based buffer overflow vulnerabilityA maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage t…EPSS 0.28%7.8CVE-2025-8893Autodesk revit out-of-bounds write vulnerabilityA maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may …EPSS 0.17%7.8CVE-2025-8894Autodesk autocad plant 3d heap-based buffer overflow vulnerabilityA maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can l…EPSS 0.17%7.8CVE-2025-5047Autodesk advance steel vulnerabilityA maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can levera…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2026-7406), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.