Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Autodesk

First CVE: Dec 31, 2005Active for: 21 yearsTotal CVEs: 364
46.7
VTI Score
High

Autodesk's vulnerability footprint spans a broadly represented portfolio of design, engineering, and construction software, with the AutoCAD family and its specialized variants dominating the exposure across architecture, electrical, mechanical, and MEP disciplines. The recurring weakness classes—out-of-bounds writes and reads, heap-based buffer overflows, use-after-free conditions, and memory-buffer boundary violations—reflect the memory-safety demands of large native codebases that process complex file formats and geometry operations. These memory-oriented flaws arise from the architectural complexity of handling untrusted CAD files and computational geometry, creating a durable attack surface tied to the desktop and server deployment of these widely used design tools. Defenders should prioritize patches for these products within design-centric environments and treat file-handling workflows as a potential ingress vector for memory-corruption attacks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
364
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Autodesk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Jun 22, 2026
32 days ago

Self-Reporting Analysis

Of all the CVEs published by Autodesk as a CNA, 99.7% affect products that Autodesk develops as a vendor.

99.7%
Self-reported: 339 (99.7%)
Third-party: 1 (0.3%)

Of all the CVEs published that affect products developed by Autodesk, 93.1% are self-published by Autodesk as a CNA.

93.1%
Self-published: 339 (93.1%)
Other CNAs: 25 (6.9%)

Products(74 total)

Top CVEs

Signals from CVEs in this vendor scope (364 CVEs).

364 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27030HIGH
A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code
Apr 19, 20217.860NONO
CVE-2026-10789CRITICAL
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that coul
Jun 22, 20269.639NONO
CVE-2008-4472HIGH
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers
Oct 7, 20089.336NOYES
CVE-2008-4471HIGH
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk De
Oct 7, 20089.335NOYES
CVE-2009-3578HIGH
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya
Nov 24, 20099.334NOYES
CVE-2009-3577HIGH
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCom
Nov 24, 20099.334NOYES
CVE-2026-7454HIGH
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbi
May 26, 20267.833NONO
CVE-2009-3576HIGH
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file
Nov 24, 20099.333NOYES
CVE-2016-9306CRITICAL
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DAE format files.
Jan 25, 20179.832NONO
CVE-2022-33882CRITICAL
Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in file delete operation in Autodesk desktop app (ADA). An attack
Oct 3, 20229.831NONO
View all 364 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products364 CVEs
92%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local320 (87.9%)
Network25 (6.9%)
Unknown19 (5.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low345 (94.8%)
High0 (0.0%)
Unknown19 (5.2%)
User Interaction
None20 (5.5%)
Unknown19 (5.2%)
Required325 (89.3%)
Privileges Required
Low5 (1.4%)
High0 (0.0%)
None340 (93.4%)
Unknown19 (5.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (364 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
1.6% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Autodesk.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Autodesk — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Autodesk's Products

View all 4 CNAs →

Top CWEs