CVE-2026-19568
published 2026-08-24CVE-2026-19568: A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.13%
3.1th percentile
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | 3ds_max | >= 2026 < 2026.3.4 | 2026.3.4 |
| autodesk | 3ds_max | >= 2026.0.0 < 2026.3.4 | 2026.3.4 |
| autodesk | 3ds_max | >= 2027 < 2027.2 | 2027.2 |
| autodesk | 3ds_max | >= 2027.0.0 < 2027.2.0 | 2027.2.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability.
ghsa_unreviewed·2026-08-24
CVE-2026-19568 [HIGH] CWE-120 A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability.
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
VulDB
Autodesk 3ds Max up to 2026.3.3 SVG Parser memory corruption (EUVD-2026-65153)
vuldb·2026-08-24·CVSS 7.8
CVE-2026-19568 [HIGH] Autodesk 3ds Max up to 2026.3.3 SVG Parser memory corruption (EUVD-2026-65153)
A vulnerability identified as critical has been detected in Autodesk 3ds Max up to 2026.3.3. This vulnerability affects unknown code of the component SVG Parser. This manipulation causes memory corruption.
This vulnerability is tracked as CVE-2026-19568. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-22990 kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental()
bugzilla·2026-01-23·CVSS 5.5
CVE-2026-22990 [MEDIUM] CVE-2026-22990 kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental()
CVE-2026-22990 kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental()
In the Linux kernel, the following vulnerability has been resolved:
libceph: replace overzealous BUG_ON in osdmap_apply_incremental()
If the osdmap is (maliciously) corrupted such that the incremental
osdmap epoch is different from what is expected, there is no need to
BUG. Instead, just declare the incremental osdmap to be invalid.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026012351-CVE-2026-22990-a62e@gregkh/T
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:19568 https://access.redhat.com/errata/RHSA-2026:19568
Bugzilla
CVE-2026-22984 kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done()
bugzilla·2026-01-23·CVSS 7.1
CVE-2026-22984 [HIGH] CVE-2026-22984 kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done()
CVE-2026-22984 kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done()
In the Linux kernel, the following vulnerability has been resolved:
libceph: prevent potential out-of-bounds reads in handle_auth_done()
Perform an explicit bounds check on payload_len to avoid a possible
out-of-bounds access in the callout.
[ idryomov: changelog ]
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026012349-CVE-2026-22984-001c@gregkh/T
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:19568 https://access.redhat.com/errata/RHSA-2026:19568
2026-08-24
Published