CVE-2026-7405: TIF File Parsing Out-of-Bounds Read in certain Autodesk products

Published Aug 6, 2026
·
Updated

A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service

Affected Software

15 affected components
Autodesk TIF file image import parsing (image handling library)
Autodesk Advance Steel>=2027<2027.1
Autodesk AutoCAD>=2027<2027.1
Autodesk AutoCAD Architecture>=2027<2027.1
Autodesk AutoCAD Electrical>=2027<2027.1
Autodesk AutoCAD LT>=2027<2027.1
Autodesk AutoCAD Map 3D>=2027<2027.1
Autodesk AutoCAD Mechanical>=2027<2027.1
Autodesk AutoCAD MEP>=2027<2027.1
Autodesk AutoCAD Plant 3D>=2027<2027.1
Autodesk Civil 3D>=2027<2027.1
Autodesk DWG TrueView>=2027<2027.1
Autodesk Revit>=2025<2025.3.5
Autodesk Revit>=2026<2026.5
Autodesk Revit>=2027<2027.1

Event History

Aug 6, 2026
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:18 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-7405?

The severity of CVE-2026-7405 is medium, with a score of 5.5.

2

What impact does CVE-2026-7405 have on affected products?

CVE-2026-7405 can lead to a denial of service by causing an out-of-bounds read when parsing maliciously crafted TIF files.

3

How do I fix CVE-2026-7405?

To mitigate CVE-2026-7405, ensure that you are using the latest version of Autodesk products that include the necessary security updates.

4

Which Autodesk products are affected by CVE-2026-7405?

CVE-2026-7405 affects certain Autodesk products that handle TIF file parsing.

5

Can exploitation of CVE-2026-7405 be remotely triggered?

Yes, exploitation of CVE-2026-7405 can be triggered by a user opening a malicious TIF file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203