
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7455 is an Out-of-Bounds Write vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted FLT file. A malicious actor may leverage this flaw to cause a crash, corrupt data, or execute arbitrary code in the context of the current process. Affected versions include Autodesk 3ds Max 2026.0.0 through 2026.3.4 (exclusive) and 2027.0.0 through 2027.2.0 (exclusive). The vulnerability was published on August 24, 2026, and carries a CVSS v3.1 base score of 7.8 (High), assigned by Autodesk (Github Advisory, Autodesk Advisory).
The root cause is classified as CWE-787 (Out-of-bounds Write), where the FLT file parser in Autodesk 3ds Max fails to properly validate input data, allowing writes beyond the bounds of an allocated buffer. Exploitation requires a local attack vector with low complexity: an attacker crafts a malicious FLT file and tricks a target user into opening it within 3ds Max, triggering the memory corruption. No privileges are required on the attacker's part, but user interaction (opening the file) is a necessary precondition. No public proof-of-concept or technical write-up detailing specific exploitation mechanics has been identified at this time (Github Advisory, Autodesk Advisory).
Successful exploitation can result in arbitrary code execution within the context of the 3ds Max process, running with the privileges of the logged-in user. Additional consequences include application crashes (denial of service) and data corruption affecting project files or other data accessible to the process. Because the attack is local and process-scoped, lateral movement potential is limited, but code execution could enable an attacker to establish persistence or access sensitive design data on the affected workstation (Github Advisory, Autodesk Advisory).
There is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation at this time. No threat actor attribution has been reported, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is 0.0, reflecting a currently low probability of exploitation (Github Advisory).
cmd.exe, powershell.exe, curl, or scripting interpreters) following the opening of an FLT file.3dsmax.exe with access violation or memory corruption errors coinciding with FLT file parsing.3dsmax.exe process shortly after a file open event, which may indicate post-exploitation activity.Autodesk has released patched versions addressing this vulnerability: users should upgrade to Autodesk 3ds Max 2026.3.4 or later (for the 2026 branch) and 2027.2.0 or later (for the 2027 branch). As interim workarounds, users should avoid opening FLT files from untrusted or unknown sources, and organizations should consider disabling FLT file import functionality if it is not operationally required. Autodesk Access can be used to manage and apply updates (Autodesk Advisory, Autodesk Access).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."