CVE-2026-16463 – Autodesk AutoCAD
“One malicious design file can turn a trusted engineering tool into an attack path.”
This patch addresses CVE-2026-16463, a Heap-Based Buffer Overflow vulnerability (CWE-122) affecting Autodesk AutoCAD. The CVSS score is 7.8, which is High severity. No verified real-world exploitation has been reported.
The vulnerability can be triggered when AutoCAD parses a specially crafted DXF file. Successful exploitation could cause the application to crash, expose sensitive data, or execute arbitrary code in the context of the current process. Exploitation requires a user to open the malicious file. Based on the supplied assessment, the vulnerability has Remote Code Execution (RCE) characteristics but does not have Elevation of Privilege (EoP) characteristics. Autodesk has released a security update to address the memory handling flaw and organizations should apply the update to affected systems.
Key Details
- Affected Product
- Autodesk Advance Steel
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-122