CVE-2026-16465: DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
Published Jul 29, 2026
·Updated
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
Affected Software
23 affected components
Autodesk AutoCAD
Autodesk Advance Steel>=2026<2026.1.2
Autodesk Advance Steel=2027
Autodesk AutoCAD>=2026<2026.1.2
Autodesk AutoCAD=2027
Autodesk AutoCAD Architecture>=2026<2026.1.2
Autodesk AutoCAD Architecture=2027
Autodesk AutoCAD Electrical>=2026<2026.1.2
Autodesk AutoCAD Electrical=2027
Autodesk AutoCAD LT>=2026<2026.1.2
Autodesk AutoCAD LT=2027
Autodesk AutoCAD Map 3D>=2026<2026.1.2
Autodesk AutoCAD Map 3D=2027
Autodesk AutoCAD Mechanical>=2026<2026.1.2
Autodesk AutoCAD Mechanical=2027
Autodesk AutoCAD MEP>=2026<2026.1.2
Autodesk AutoCAD MEP=2027
Autodesk AutoCAD Plant 3D>=2026<2026.1.2
Autodesk AutoCAD Plant 3D=2027
Autodesk Civil 3D>=2026<2026.1.2
Autodesk Civil 3D=2027
Autodesk DWG TrueView>=2026<2026.1.2
Autodesk DWG TrueView=2027
Event History
Jul 29, 2026
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Mar 3, 58579
Event
via NVD·02:59 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-16465?
The severity of CVE-2026-16465 is medium with a score of 6.1.
2
How do I fix CVE-2026-16465?
To fix CVE-2026-16465, ensure that you are using the latest version of Autodesk AutoCAD with security updates applied.
3
What types of files are associated with CVE-2026-16465?
CVE-2026-16465 is associated with DWG and DXF file formats.
4
What can an attacker do with CVE-2026-16465?
An attacker can exploit CVE-2026-16465 to cause a crash or potentially disclose sensitive information.
5
What is the impact of CVE-2026-16465 on Autodesk AutoCAD users?
The impact of CVE-2026-16465 on Autodesk AutoCAD users includes the risk of application crashes and exposure of sensitive data when opening malicious files.