cbcvebase.
CVE-2026-10789
published 2026-06-22

CVE-2026-10789: A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the…

PriorityP357critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
0.38%
30.6th percentile
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.

Affected

2 ranges
VendorProductVersion rangeFixed in
autodeskfusion< 2703.1.202703.1.20
autodeskfusion>= 2703.1.11 < 2703.1.202703.1.20
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.