CVE-2026-0659
published 2026-02-04CVE-2026-0659: A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.21%
11.3th percentile
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | 3ds_max | >= 2026.2 < 2026.3.2 | 2026.3.2 |
| autodesk | arnold | >= 7.4.4.1 < 7.4.4.2 | 7.4.4.2 |
| autodesk | usd_for_arnold | >= 7.4.4.1 < 7.4.4.2 | 7.4.4.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0662 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0662 [HIGH] CVE-2026-0662 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0662 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
## Get a CVE risk
Wiz
CVE-2026-0661 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0661 [HIGH] CVE-2026-0661 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0661 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
#
Wiz
CVE-2026-0659 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0659 [HIGH] CVE-2026-0659 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0659 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
NVD
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
## Get a CVE risk a
Wiz
CVE-2026-0536 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0536 [HIGH] CVE-2026-0536 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0536 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
## Get a CVE risk assessment
Get a prioriti
Wiz
CVE-2026-0660 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0660 [HIGH] CVE-2026-0660 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0660 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09
Wiz
CVE-2026-0538 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0538 [HIGH] CVE-2026-0538 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0538 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
Wiz
CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0537 [HIGH] CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0537 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
#
2026-02-04
Published