Junglewise Threat Intelligence

CVE-2026-16465: Autodesk AutoCAD out-of-bounds read in DWG and DXF parsing

CVE-2026-16465 · Severity: medium · CVSS 6.1 · Published 2026-07-29

Technologies: Autodesk DWG TrueView, Autodesk AutoCAD, Autodesk AutoCAD LT. Vendors: Autodesk.

Executive brief

Autodesk AutoCAD and related design software are susceptible to a vulnerability when processing specially crafted drawing files. If a user opens a malicious DWG or DXF file, the application may crash or inadvertently reveal sensitive information from the computer's memory. This could lead to a loss of productivity due to software instability or the unauthorized disclosure of internal data.

Technical details

An Out-of-Bounds Read vulnerability (CWE-125) exists in Autodesk AutoCAD, AutoCAD LT, and DWG TrueView when parsing maliciously crafted DWG or DXF files. The issue occurs because the application does not properly validate the boundaries of the data being read from the file. An attacker can exploit this by tricking a user into opening a specially crafted file, leading to a denial-of-service (crash) or the disclosure of sensitive information from the process memory. The vulnerability affects version 2027.0.0 and is addressed in version 2027.1.0. Exploitation requires local access and user interaction to open the malicious file.

Affected products

  • Autodesk AutoCAD 2027.0.0 to 2027.1.0
  • Autodesk AutoCAD LT 2027.0.0 to 2027.1.0
  • Autodesk DWG TrueView 2027.0.0 to 2027.1.0

Timeline

  • 2026-07-29: disclosed: Initial advisory published by Autodesk
  • 2026-07-29: advisory: NVD entry created

References

Related threats