« Back to list

Autodesk

Autodesk Autocad: vulnerabilities and CVEs

Autodesk Autocad has 168 published vulnerabilities, 5 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs168
Last 12 months5
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-7406High (7.8)0.19%—Aug 6, 2026
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the…
CVE-2026-7405Medium (5.5)0.16%—Aug 6, 2026
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to…
CVE-2026-17550Medium (5.5)0.25%—Jul 29, 2026
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive…
CVE-2026-16465High (7.1)0.26%—Jul 29, 2026
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive…
CVE-2026-16463High (7.8)0.28%—Jul 29, 2026
A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute…
CVE-2025-8894High (7.8)0.17%—Sep 16, 2025
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or…
CVE-2025-8893High (7.8)0.17%—Sep 16, 2025
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption,…
CVE-2025-5048High (7.8)0.18%—Aug 15, 2025
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of…
CVE-2025-5047High (7.8)0.18%—Aug 15, 2025
A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or…
CVE-2025-5046High (7.8)0.18%—Aug 15, 2025
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or…
CVE-2025-1276High (7.8)0.29%—Apr 15, 2025
A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data…
CVE-2025-1275High (7.8)0.38%—Apr 15, 2025
A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read…
CVE-2025-1652High (7.8)0.23%—Mar 13, 2025
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute…
CVE-2025-1651High (7.8)0.23%—Mar 13, 2025
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute…
CVE-2025-1650High (7.8)0.23%—Mar 13, 2025
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or…
CVE-2025-1649High (7.8)0.23%—Mar 13, 2025
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or…
CVE-2025-1433High (7.8)0.23%—Mar 13, 2025
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute…
CVE-2025-1432High (7.8)0.28%—Mar 13, 2025
A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute…
CVE-2025-1431High (7.8)0.23%—Mar 13, 2025
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute…
CVE-2025-1430High (7.8)0.23%—Mar 13, 2025
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the…
CVE-2025-1429High (7.8)0.23%—Mar 13, 2025
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute…
CVE-2025-1428High (7.8)0.28%—Mar 13, 2025
A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or…
CVE-2025-1427High (7.8)0.25%—Mar 13, 2025
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or…
CVE-2024-9997High (7.8)0.21%—Oct 29, 2024
A maliciously crafted DWG file when parsed in acdb25.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or…
CVE-2024-9996High (7.8)0.21%—Oct 29, 2024
A maliciously crafted DWG file, when parsed in acdb25.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data…
CVE-2024-9827High (7.8)0.21%—Oct 29, 2024
A maliciously crafted CATPART file when parsed in CC5Dll.dll through Autodesk AutoCAD can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive…
CVE-2024-9826High (7.8)0.22%—Oct 29, 2024
A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or…
CVE-2024-9489High (7.8)0.21%—Oct 29, 2024
A maliciously crafted DWG file when parsed in ACAD.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or…
CVE-2024-8896High (7.8)0.20%—Oct 29, 2024
A maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior to initialization. A malicious actor can leverage this vulnerability to cause a crash, write…
CVE-2024-8600High (7.8)0.21%—Oct 29, 2024
A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1203 Exploitation for Client Execution21
  2. T1059 Command and Scripting Interpreter18
  3. T1005 Data from Local System1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Autodesk