
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0537 is a memory corruption vulnerability in Autodesk 3ds Max's RGB file parser that allows arbitrary code execution in the context of the current process. It affects Autodesk 3ds Max versions 2026 through 2026.3.1 (i.e., all 2026 releases prior to 2026.3.2). The vulnerability was published on February 4, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 8.4 (High) per NVD, or 7.8 (High) per the ENISA/Autodesk scoring that accounts for required user interaction (Autodesk Advisory, Red Hat CVE).
The root cause is an out-of-bounds write (CWE-787) triggered during the parsing of a maliciously crafted RGB image file within Autodesk 3ds Max. When the application processes such a file, improper memory handling leads to a memory corruption condition that can be leveraged to redirect execution flow and run attacker-controlled code. Exploitation requires a user to open a malicious RGB file (user interaction), but no special privileges are needed. No public proof-of-concept or detailed technical write-up has been identified at this time (Autodesk Advisory, Red Hat CVE).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Autodesk 3ds Max, resulting in high confidentiality, integrity, and availability impacts. This could enable unauthorized access to sensitive project files and system data, modification or deletion of files, and disruption of the application or underlying system. The attack is limited to the local context (the user must open a malicious file), but in creative or engineering environments where RGB files are routinely shared, the risk of social engineering-based delivery is meaningful (Autodesk Advisory).
cmd.exe, powershell.exe, curl, wget); unexpected network connections initiated by the 3ds Max process.Autodesk has released a patch in version 2026.3.2, which resolves this vulnerability. Users should update Autodesk 3ds Max 2026 to version 2026.3.2 or later as the primary remediation. Until patching is complete, users should avoid opening RGB files from untrusted or unverified sources, and administrators should consider restricting file sharing of RGB assets from external parties. Implementing application-level monitoring for unusual process behavior from 3ds Max is also recommended as a compensating control (Autodesk Advisory).
The vulnerability received routine coverage from vulnerability tracking services and security feeds shortly after disclosure, including mentions on Mastodon via TheHackerWire and aggregation by platforms such as VulDB, CVEFeed, and RedPacket Security. No significant vendor statements beyond the Autodesk security advisory, nor notable independent researcher commentary or media investigations, have been identified for this CVE (Autodesk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."