CVE-2026-8325
published 2026-08-06CVE-2026-8325: A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.13%
3.1th percentile
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | revit | >= 2026.0.0 < 2026.5.0 | 2026.5.0 |
| autodesk | revit | >= 2027.0.0 < 2027.2.0 | 2027.2.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability.
ghsa_unreviewed·2026-08-07
CVE-2026-8325 [HIGH] CWE-787 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability.
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
VulDB
Autodesk Revit prior 2026.5.0/2027.2.0 PDF file out-of-bounds write
vuldb·2026-08-07·CVSS 7.8
CVE-2026-8325 [HIGH] Autodesk Revit prior 2026.5.0/2027.2.0 PDF file out-of-bounds write
A vulnerability was found in Autodesk Revit. It has been classified as critical. This vulnerability affects unknown code of the component PDF file Handler. Performing a manipulation results in out-of-bounds write.
This vulnerability is known as CVE-2026-8325. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-06
Published