CVE-2026-0662
published 2026-02-04CVE-2026-0662: A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.18%
8.0th percentile
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | 3ds_max | >= 2026 < 2026.3.2 | 2026.3.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j98v-582h-h35h: A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the
ghsa_unreviewed·2026-02-04
CVE-2026-0662 [HIGH] CWE-426 GHSA-j98v-582h-h35h: A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
Red Hat
vim: Vim: Denial of Service via crafted spell file
vendor_redhat·2026-06-25·CVSS 5.5
CVE-2026-55892 [MEDIUM] CWE-787 vim: Vim: Denial of Service via crafted spell file
vim: Vim: Denial of Service via crafted spell file
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.
A flaw was found in Vim, an open-source command-line text
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0662 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0662 [HIGH] CVE-2026-0662 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0662 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
## Get a CVE risk
Wiz
CVE-2026-0661 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0661 [HIGH] CVE-2026-0661 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0661 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
#
Wiz
CVE-2026-0659 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0659 [HIGH] CVE-2026-0659 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0659 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
NVD
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
## Get a CVE risk a
Wiz
CVE-2026-0536 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0536 [HIGH] CVE-2026-0536 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0536 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 7.8
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
## Get a CVE risk assessment
Get a prioriti
Wiz
CVE-2026-0660 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0660 [HIGH] CVE-2026-0660 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0660 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09
Wiz
CVE-2026-0538 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0538 [HIGH] CVE-2026-0538 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0538 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
Wiz
CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-0537 [HIGH] CVE-2026-0537 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0537 :
Autodesk 3ds Max vulnerability analysis and mitigation
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Source : NVD
## 8.4
Score
Published February 4, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Autodesk 3ds Max
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:autodesk:3ds_max
Sources
Windows Severity HIGH Has Fix Added at: Feb 08, 2026
Windows Severity HIGH Has Fix Added at: Feb 09, 2026
#
Bugzilla
CVE-2026-55892 vim: Vim: Denial of Service via crafted spell file
bugzilla·2026-06-25·CVSS 5.5
CVE-2026-55892 [MEDIUM] CVE-2026-55892 vim: Vim: Denial of Service via crafted spell file
CVE-2026-55892 vim: Vim: Denial of Service via crafted spell file
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.
2026-02-04
Published