
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19568 is a memory corruption vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted SVG file, allowing an attacker to execute arbitrary code in the context of the current process. It affects Autodesk 3ds Max versions 2026.0.0 through 2026.3.4 (exclusive) and 2027.0.0 through 2027.2.0 (exclusive). The vulnerability was published on August 24, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.8 (High), assigned by Autodesk (GitHub Advisory, Autodesk Advisory).
The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input / Classic Buffer Overflow), where the SVG parser in 3ds Max copies input data into a buffer without validating that the input size does not exceed the destination buffer's capacity, resulting in memory corruption. The attack vector is local, requiring no special privileges but necessitating user interaction — specifically, a victim must open a maliciously crafted SVG file within 3ds Max. Feedly's estimate also associates CWE-787 (Out-of-bounds Write) as a likely related weakness, consistent with the memory corruption outcome (GitHub Advisory, Autodesk Advisory).
Successful exploitation grants an attacker arbitrary code execution within the context of the 3ds Max process, resulting in high confidentiality, integrity, and availability impact on the affected workstation. An attacker could access sensitive project files, intellectual property, or credentials stored on the system, modify or destroy 3ds Max assets, or crash the application. While the scope is limited to the current process and does not directly imply privilege escalation, code execution could serve as a foothold for further lateral movement within a network (GitHub Advisory, Autodesk Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is reported as 0.0, indicating a very low current probability of exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.
cmd.exe, powershell.exe, curl, wget); 3ds Max process crashing or exhibiting abnormal memory usage after opening an SVG file.3dsmax.exe) with access violation or heap corruption errors; Windows Event Log entries (Event ID 1000/1001) indicating faulting module related to SVG parsing.Autodesk has released patched versions: 3ds Max 2026.3.4 and 3ds Max 2027.2.0, which address this vulnerability. Users should update to these versions or later via the Autodesk Access tool. As an interim workaround, avoid opening SVG files from untrusted or unverified sources in 3ds Max, and implement file type filtering or access controls to prevent loading potentially malicious SVG files into the application (Autodesk Advisory, GitHub Advisory).
The vulnerability received limited public attention at the time of disclosure, with automated aggregation by vulnerability tracking services (VulDB, CVEFeed, Vulners) and a brief mention on Mastodon via The Hacker Wire. No significant researcher commentary or media coverage beyond standard vulnerability database entries has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."