Autodesk's vulnerability footprint spans a broadly represented portfolio of design, engineering, and construction software, with the AutoCAD family and its specialized variants dominating the exposure across architecture, electrical, mechanical, and MEP disciplines. The recurring weakness classes—out-of-bounds writes and reads, heap-based buffer overflows, use-after-free conditions, and memory-buffer boundary violations—reflect the memory-safety demands of large native codebases that process complex file formats and geometry operations. These memory-oriented flaws arise from the architectural complexity of handling untrusted CAD files and computational geometry, creating a durable attack surface tied to the desktop and server deployment of these widely used design tools. Defenders should prioritize patches for these products within design-centric environments and treat file-handling workflows as a potential ingress vector for memory-corruption attacks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Autodesk over time
Of all the CVEs published by Autodesk as a CNA, 99.7% affect products that Autodesk develops as a vendor.
Of all the CVEs published that affect products developed by Autodesk, 93.1% are self-published by Autodesk as a CNA.
Signals from CVEs in this vendor scope (364 CVEs).
364 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27030HIGH A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code | Apr 19, 2021 | 7.8 | 60 | NO | NO |
CVE-2026-10789CRITICAL A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that coul | Jun 22, 2026 | 9.6 | 39 | NO | NO |
CVE-2008-4472HIGH The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers | Oct 7, 2008 | 9.3 | 36 | NO | YES |
CVE-2008-4471HIGH Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk De | Oct 7, 2008 | 9.3 | 35 | NO | YES |
CVE-2009-3578HIGH Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya | Nov 24, 2009 | 9.3 | 34 | NO | YES |
CVE-2009-3577HIGH Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCom | Nov 24, 2009 | 9.3 | 34 | NO | YES |
CVE-2026-7454HIGH A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbi | May 26, 2026 | 7.8 | 33 | NO | NO |
CVE-2009-3576HIGH Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file | Nov 24, 2009 | 9.3 | 33 | NO | YES |
CVE-2016-9306CRITICAL Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DAE format files. | Jan 25, 2017 | 9.8 | 32 | NO | NO |
CVE-2022-33882CRITICAL Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in file delete operation in Autodesk desktop app (ADA). An attack | Oct 3, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (364 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Autodesk.
Media articles that mention a CVE ID that affects a product developed by Autodesk — matched by CVE ID, not by vendor name.