CVE-2026-0660
published 2026-02-04CVE-2026-0660: A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage…
PriorityP349high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.19%
8.7th percentile
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | 3ds_max | >= 2026 < 2026.3.2 | 2026.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
ghsa·2026-06-19
CVE-2026-54776 [MEDIUM] CWE-306 CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
### Impact
A CoreWCF service hosted on Unix Domain Sockets with the PosixIdentity client credential type (UnixDomainSocketBinding with Security.Mode = TransportCredentialOnly and Security.Transport.ClientCredentialType = PosixIdentity) does not require the client to perform the application/unixposix stream upgrade before dispatching messages.
### Patches
Fixed in CoreWCF v1.8.1 and v1.9.1
### Workarounds
Restrict filesystem access to the UDS socket file using owner/group/mode (e.g. chmod 0660 plus a dedicated group) so that only the POSIX users who are already authorized to invoke the service can connect at all. This makes the missing-upgrade behaviour equivalent to the operating syste
VulDB
Autodesk 3ds Max up to 2026.3.1 GIF File Parser stack-based overflow
vuldb·2026-06-04·CVSS 8.4
CVE-2026-0660 [HIGH] Autodesk 3ds Max up to 2026.3.1 GIF File Parser stack-based overflow
A vulnerability classified as critical has been found in Autodesk 3ds Max up to 2026.3.1. Impacted is an unknown function of the component GIF File Parser. This manipulation causes stack-based buffer overflow.
This vulnerability is handled as CVE-2026-0660. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-wpv7-jq7x-9x2j: A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability
ghsa_unreviewed·2026-02-04
CVE-2026-0660 [HIGH] CWE-121 GHSA-wpv7-jq7x-9x2j: A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0662 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0662 [HIGH] CVE-2026-0662 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0662 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
## Get a CVE risk
Wiz
CVE-2026-0661 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0661 [HIGH] CVE-2026-0661 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0661 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
#
Wiz
CVE-2026-0659 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0659 [HIGH] CVE-2026-0659 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0659 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
NVD
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
## Get a CVE risk a
Wiz
CVE-2026-0536 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0536 [HIGH] CVE-2026-0536 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0536 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
## Get a CVE risk assessment
Get a prioriti
Wiz
CVE-2026-0660 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0660 [HIGH] CVE-2026-0660 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0660 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09
Wiz
CVE-2026-0538 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0538 [HIGH] CVE-2026-0538 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0538 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
Wiz
CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0537 [HIGH] CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0537 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
#
2026-02-04
Published