
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16783 is an Out-of-Bounds Write vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted ABC file. It affects Autodesk 3ds Max versions 2026.0.0 through 2026.3.4 (exclusive) and 2027.0.0 through 2027.2.0 (exclusive). The vulnerability was published on August 24, 2026, and carries a CVSS v3.1 base score of 7.8 (High), assigned by Autodesk (GitHub Advisory, Autodesk Advisory).
The root cause is an Out-of-Bounds Write (CWE-787) in 3ds Max's ABC file parser, where insufficient bounds checking allows a specially crafted ABC file to write data beyond the boundaries of an allocated buffer. The attack vector is local, requiring no privileges but necessitating user interaction — specifically, a victim must open the malicious ABC file within 3ds Max. Exploitation relies on social engineering to deliver the crafted file to a target user, after which the parser processes the malformed data and triggers the memory corruption (GitHub Advisory, Autodesk Advisory).
Successful exploitation can result in application crashes (denial of service), data corruption, or arbitrary code execution within the context of the current 3ds Max process. Because the code executes under the privileges of the logged-in user, an attacker could access sensitive files, install malware, or use the compromised workstation as a pivot point for further lateral movement within a network. The high confidentiality, integrity, and availability impact ratings reflect the full compromise potential of the affected process (GitHub Advisory, Autodesk Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is 0.0, indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
cmd.exe, powershell.exe, curl, wget) that are not part of normal application behavior; 3ds Max process crashing unexpectedly after opening an ABC file.Autodesk has released patched versions addressing this vulnerability: users should update to 3ds Max 2026.3.4 or later for the 2026 branch, and 3ds Max 2027.2.0 or later for the 2027 branch. As interim mitigations, users should avoid opening ABC files from untrusted or unknown sources, and organizations should educate staff about the risks of opening unsolicited 3D asset files. Additional hardening measures include implementing application sandboxing for file parsing operations and restricting file handling capabilities where feasible (Autodesk Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."