CVE-2026-7406
published 2026-08-06CVE-2026-7406: A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.13%
3.2th percentile
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | autocad | >= 2026.0.0 < 2026.1.2 | 2026.1.2 |
| autodesk | autocad | >= 2027.0.0 < 2027.1.0 | 2027.1.0 |
| autodesk | autocad_lt | >= 2026.0.0 < 2026.1.2 | 2026.1.2 |
| autodesk | autocad_lt | >= 2027.0.0 < 2027.1.0 | 2027.1.0 |
| autodesk | dwg_trueview | >= 2026.0.0 < 2026.1.2 | 2026.1.2 |
| autodesk | dwg_trueview | >= 2027.0.0 < 2027.1.0 | 2027.1.0 |
| autodesk | revit | >= 2024.0.0 < 2024.3.5 | 2024.3.5 |
| autodesk | revit | >= 2026.0.0 < 2026.5.0 | 2026.5.0 |
| autodesk | revit | >= 2027.0.0 < 2027.1.0 | 2027.1.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability.
ghsa_unreviewed·2026-08-07
CVE-2026-7406 [HIGH] CWE-822 A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability.
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
VulDB
Autodesk AutoCAD/AutoCAD LT/Revit BMP file null pointer dereference
vuldb·2026-08-07·CVSS 7.8
CVE-2026-7406 [HIGH] Autodesk AutoCAD/AutoCAD LT/Revit BMP file null pointer dereference
A vulnerability was found in Autodesk AutoCAD, AutoCAD LT and Revit and classified as critical. This affects an unknown part of the component BMP file Handler. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2026-7406. The attack may be launched remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-06
Published