CVE-2026-0661
published 2026-02-04CVE-2026-0661: A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this…
PriorityP346high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.18%
7.2th percentile
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | 3ds_max | >= 2026 < 2026.3.2 | 2026.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Autodesk 3ds Max up to 2026.3.1 RGB File Parser out-of-bounds write
vuldb·2026-06-04·CVSS 8.4
CVE-2026-0661 [HIGH] Autodesk 3ds Max up to 2026.3.1 RGB File Parser out-of-bounds write
A vulnerability described as critical has been identified in Autodesk 3ds Max up to 2026.3.1. This issue affects some unknown processing of the component RGB File Parser. The manipulation results in out-of-bounds write.
This vulnerability is known as CVE-2026-0661. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-gqqf-v25p-495h: A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability
ghsa_unreviewed·2026-02-04
CVE-2026-0661 [HIGH] CWE-787 GHSA-gqqf-v25p-495h: A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0662 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0662 [HIGH] CVE-2026-0662 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0662 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
## Get a CVE risk
Wiz
CVE-2026-0661 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0661 [HIGH] CVE-2026-0661 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0661 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
#
Wiz
CVE-2026-0659 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0659 [HIGH] CVE-2026-0659 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0659 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
NVD
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
## Get a CVE risk a
Wiz
CVE-2026-0536 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0536 [HIGH] CVE-2026-0536 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0536 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
## Get a CVE risk assessment
Get a prioriti
Wiz
CVE-2026-0660 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0660 [HIGH] CVE-2026-0660 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0660 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09
Wiz
CVE-2026-0538 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0538 [HIGH] CVE-2026-0538 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0538 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
Wiz
CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0537 [HIGH] CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0537 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
#
2026-02-04
Published