CVE-2026-0537
published 2026-02-04CVE-2026-0537: A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this…
PriorityP346high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.17%
6.8th percentile
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | 3ds_max | >= 2026 < 2026.3.2 | 2026.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Autodesk 3ds Max up to 2026.3.1 RGB File Parser out-of-bounds write (Nessus ID 298246)
vuldb·2026-06-04·CVSS 8.4
CVE-2026-0537 [HIGH] Autodesk 3ds Max up to 2026.3.1 RGB File Parser out-of-bounds write (Nessus ID 298246)
A vulnerability labeled as critical has been found in Autodesk 3ds Max up to 2026.3.1. This affects an unknown part of the component RGB File Parser. Executing a manipulation can lead to out-of-bounds write.
This vulnerability appears as CVE-2026-0537. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
GHSA
GHSA-7pw6-2xv6-25xh: A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability
ghsa_unreviewed·2026-02-04
CVE-2026-0537 [HIGH] CWE-787 GHSA-7pw6-2xv6-25xh: A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0537 [HIGH] CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0537 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
#
Bugzilla
CVE-2023-53705 kernel: ipv6: Fix out-of-bounds access in ipv6_find_tlv()
bugzilla·2025-10-22
CVE-2023-53705 [MEDIUM] CVE-2023-53705 kernel: ipv6: Fix out-of-bounds access in ipv6_find_tlv()
CVE-2023-53705 kernel: ipv6: Fix out-of-bounds access in ipv6_find_tlv()
In the Linux kernel, the following vulnerability has been resolved:
ipv6: Fix out-of-bounds access in ipv6_find_tlv()
optlen is fetched without checking whether there is more than one byte to parse.
It can lead to out-of-bounds access.
Found by InfoTeCS on behalf of Linux Verification Center
(linuxtesting.org) with SVACE.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025102212-CVE-2023-53705-38d9@gregkh/T
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Via RHSA-2026:0537 https://access.redhat.com/errata/RHSA-2026:0537
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux
2026-02-04
Published