Junglewise Threat Intelligence

CVE-2026-16463: Autodesk AutoCAD heap overflow in DXF parsing

CVE-2026-16463 · Severity: high · CVSS 7.8 · Published 2026-07-29

Technologies: Autodesk DWG TrueView, Autodesk AutoCAD, Autodesk AutoCAD LT. Vendors: Autodesk.

Executive brief

Autodesk AutoCAD and related design software are used by engineers and architects to create and view technical drawings. A security flaw allows a malicious actor to create a specially crafted DXF file that, when opened by a user, can cause the software to crash, expose sensitive data, or allow the attacker to take control of the computer. This risk is primarily realized when users open untrusted files from external sources.

Technical details

A heap-based buffer overflow (CWE-122) exists in Autodesk AutoCAD, AutoCAD LT, and DWG TrueView when parsing specially crafted DXF files. The vulnerability is triggered during the processing of malformed file structures, leading to memory corruption. An attacker can exploit this by tricking a user into opening a malicious DXF file (local attack vector requiring user interaction). Successful exploitation can result in arbitrary code execution, information disclosure, or a denial-of-service (crash) within the context of the application process. Affected versions include the 2027 release cycle prior to version 2027.1.0.

Affected products

  • Autodesk AutoCAD 2027.0.0 to 2027.1.0
  • Autodesk AutoCAD LT 2027.0.0 to 2027.1.0
  • Autodesk DWG TrueView 2027.0.0 to 2027.1.0

Timeline

  • 2026-07-29: advisory: Initial advisory published by Autodesk and NVD.

References

Related threats