CVE-2026-7455
Autodesk 3ds Max vulnerability analysis and mitigation

Overview

CVE-2026-7455 is an Out-of-Bounds Write vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted FLT file. A malicious actor may leverage this flaw to cause a crash, corrupt data, or execute arbitrary code in the context of the current process. Affected versions include Autodesk 3ds Max 2026.0.0 through 2026.3.4 (exclusive) and 2027.0.0 through 2027.2.0 (exclusive). The vulnerability was published on August 24, 2026, and carries a CVSS v3.1 base score of 7.8 (High), assigned by Autodesk (Github Advisory, Autodesk Advisory).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write), where the FLT file parser in Autodesk 3ds Max fails to properly validate input data, allowing writes beyond the bounds of an allocated buffer. Exploitation requires a local attack vector with low complexity: an attacker crafts a malicious FLT file and tricks a target user into opening it within 3ds Max, triggering the memory corruption. No privileges are required on the attacker's part, but user interaction (opening the file) is a necessary precondition. No public proof-of-concept or technical write-up detailing specific exploitation mechanics has been identified at this time (Github Advisory, Autodesk Advisory).

Impact

Successful exploitation can result in arbitrary code execution within the context of the 3ds Max process, running with the privileges of the logged-in user. Additional consequences include application crashes (denial of service) and data corruption affecting project files or other data accessible to the process. Because the attack is local and process-scoped, lateral movement potential is limited, but code execution could enable an attacker to establish persistence or access sensitive design data on the affected workstation (Github Advisory, Autodesk Advisory).

Exploitability

There is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation at this time. No threat actor attribution has been reported, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is 0.0, reflecting a currently low probability of exploitation (Github Advisory).

Exploitation steps

  1. Craft malicious FLT file: Create a specially crafted FLT file with malformed data designed to trigger an out-of-bounds write in Autodesk 3ds Max's FLT file parser.
  2. Social engineering delivery: Deliver the malicious FLT file to a target user via email attachment, file share, or other means, disguising it as a legitimate 3D asset or scene file.
  3. User opens the file: The target user opens the crafted FLT file in a vulnerable version of Autodesk 3ds Max (2026.0.0–2026.3.3 or 2027.0.0–2027.1.x).
  4. Trigger out-of-bounds write: The FLT parser processes the malformed file, writing data beyond the intended buffer boundary, corrupting adjacent memory.
  5. Achieve code execution or crash: Depending on the memory layout and payload, the attacker achieves arbitrary code execution in the context of the 3ds Max process, or causes a crash/data corruption (Autodesk Advisory, Github Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Autodesk 3ds Max process (e.g., cmd.exe, powershell.exe, curl, or scripting interpreters) following the opening of an FLT file.
  • File System: Presence of suspicious or unknown FLT files in user download directories, temp folders, or shared drives; unexpected new files created in the 3ds Max installation or user profile directories after opening an FLT file.
  • Logs: Application crash logs or Windows Event Log entries (Event ID 1000/1001) referencing 3dsmax.exe with access violation or memory corruption errors coinciding with FLT file parsing.
  • Network: Unusual outbound network connections originating from the 3dsmax.exe process shortly after a file open event, which may indicate post-exploitation activity.

Mitigation and workarounds

Autodesk has released patched versions addressing this vulnerability: users should upgrade to Autodesk 3ds Max 2026.3.4 or later (for the 2026 branch) and 2027.2.0 or later (for the 2027 branch). As interim workarounds, users should avoid opening FLT files from untrusted or unknown sources, and organizations should consider disabling FLT file import functionality if it is not operationally required. Autodesk Access can be used to manage and apply updates (Autodesk Advisory, Autodesk Access).

Additional resources


SourceThis report was generated using AI

Related Autodesk 3ds Max vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7455HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesAug 24, 2026
CVE-2026-19568HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesAug 24, 2026
CVE-2026-16783HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesAug 24, 2026
CVE-2026-16781MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesAug 24, 2026
CVE-2026-16782MEDIUM5.3
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management