
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0661 is a memory corruption vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted RGB file, enabling arbitrary code execution in the context of the current process. It affects Autodesk 3ds Max versions 2026 through 2026.3.1 (i.e., versions starting from 2026 up to but not including 2026.3.2). The vulnerability was published on February 4, 2026, with a patch advisory released shortly after. It carries a CVSS v3.1 base score of 8.4 (High) per NVD, and 7.8 (High) per the ENISA/Autodesk scoring (Autodesk Advisory, Red Hat CVE).
The root cause is classified as CWE-787 (Out-of-bounds Write): when Autodesk 3ds Max parses a specially crafted RGB image file, it writes data beyond the bounds of an allocated memory buffer, resulting in memory corruption. This local attack vector requires no special privileges, though the ENISA/Autodesk scoring notes that user interaction (opening a malicious file) is required. An attacker would need to convince a target user to open a weaponized RGB file, after which the out-of-bounds write can be leveraged to redirect execution flow and run arbitrary code with the privileges of the 3ds Max process (Autodesk Advisory, Red Hat CVE).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Autodesk 3ds Max, resulting in high confidentiality, integrity, and availability impact. This could lead to complete compromise of the application context, theft of sensitive project or design data, system manipulation, and potential lateral movement within the affected environment. The scope is limited to the current process context, but the full triad of CIA impacts is affected (Autodesk Advisory).
.rgb files in user download directories, temp folders, or email attachment staging areas; unusual files written to disk by the 3ds Max process.cmd.exe, powershell.exe, curl, or other shells/utilities); 3ds Max process crashing or exhibiting abnormal behavior upon opening an RGB file.Autodesk has released a patch in version 2026.3.2, which resolves this vulnerability. Users running Autodesk 3ds Max 2026 through 2026.3.1 should update to version 2026.3.2 or later immediately. As interim mitigations, restrict users from opening RGB files from untrusted or unknown sources, implement application whitelisting, and educate users about the risks of opening files from unverified origins. Monitor for suspicious process behavior associated with 3ds Max installations (Autodesk Advisory).
Coverage of CVE-2026-0661 has been limited to automated vulnerability tracking platforms and aggregators such as VulnDB, CVEFeed, RedPacket Security, and Tenable's plugin pipeline. No notable independent researcher commentary, vendor statements beyond the official Autodesk advisory, or significant social media discussion has been identified. The vulnerability received brief mention on Bluesky via The Hacker Wire's automated CVE feed (Autodesk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."