cbcvebase.
CVE-2026-1288
published 2026-06-17

CVE-2026-1288: A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability…

PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.12%
1.9th percentile
A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.

Affected

8 ranges
VendorProductVersion rangeFixed in
autodeskrevit>= 2024 < 2024.3.52024.3.5
autodeskrevit>= 2024.0.0 < 2024.3.52024.3.5
autodeskrevit>= 2025 < 2025.4.52025.4.5
autodeskrevit>= 2025.0.0 < 2025.4.52025.4.5
autodeskrevit>= 2026 < 2026.4.12026.4.1
autodeskrevit>= 2026.0.0 < 2026.4.12026.4.1
autodeskrevit>= 2027 < 2027.12027.1
autodeskrevit>= 2027.0.0 < 2027.1.02027.1.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
cvelistv5v3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.