{"schema_version":1,"title":"Autodesk <UNKNOWN> vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in Autodesk <UNKNOWN>: 4 in the last 7 days and 18 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-71458, was published on 23 September 2026.","url":"https://junglewise.ai/threats/technologies/unknown","json_url":"https://junglewise.ai/threats/technologies/unknown.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/unknown","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":8,"all_time":20,"critical":1,"exploited":0,"last_7_days":4,"last_30_days":17,"last_90_days":18,"last_365_days":20},"latest":[{"cve":"CVE-2026-71458","cvss":5,"epss":0.003,"slug":"cve-2026-71458-urlmodificationmiddleware-resolves-named-url-lookups-against","title":"URLModificationMiddleware information disclosure before RBAC enforcement","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:01.477+00:00","url":"https://junglewise.ai/threats/cve-2026-71458-urlmodificationmiddleware-resolves-named-url-lookups-against"},{"cve":"CVE-2026-25255","cvss":8.8,"epss":0.0012,"slug":"cve-2026-25255-exposed-dangerous-function-lead-to-privilege-escalation-via-grpc","title":"gRPC server exposed dangerous function privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-22T10:17:08.847+00:00","url":"https://junglewise.ai/threats/cve-2026-25255-exposed-dangerous-function-lead-to-privilege-escalation-via-grpc"},{"cve":"CVE-2026-25254","cvss":9.8,"epss":0.005,"slug":"cve-2026-25254-improper-authorization-leads-to-remote-code-execution-via","title":"SocketIO improper authorization remote code execution","severity":"critical","exploited":false,"published_at":"2026-09-22T10:17:08.583+00:00","url":"https://junglewise.ai/threats/cve-2026-25254-improper-authorization-leads-to-remote-code-execution-via"},{"cve":"CVE-2026-77165","cvss":6.5,"epss":0.0037,"slug":"cve-2026-77165-file-owners-were-unable-to-unlock-type-token-locks-placed-by","title":"Database file locking denial of service via TYPE_TOKEN locks","severity":"medium","exploited":false,"published_at":"2026-09-21T16:17:23.863+00:00","url":"https://junglewise.ai/threats/cve-2026-77165-file-owners-were-unable-to-unlock-type-token-locks-placed-by"},{"cve":"CVE-2026-68493","cvss":3.1,"epss":0.0023,"slug":"cve-2026-68493-circle-membership-enumeration-via-brute-force-identifier-guessing","title":"Circle membership enumeration via brute-force identifier guessing","severity":"low","exploited":false,"published_at":"2026-09-18T02:17:07.35+00:00","url":"https://junglewise.ai/threats/cve-2026-68493-circle-membership-enumeration-via-brute-force-identifier-guessing"},{"cve":"CVE-2026-68070","cvss":8.8,"epss":0.0043,"slug":"cve-2026-68070-authentication-bypass-with-unauthenticated-root-command-execution","title":"Authentication bypass with unauthenticated root command execution","severity":"high","exploited":false,"published_at":"2026-09-15T21:16:42.253+00:00","url":"https://junglewise.ai/threats/cve-2026-68070-authentication-bypass-with-unauthenticated-root-command-execution"},{"cve":"CVE-2026-90456","epss":0.0041,"slug":"cve-2026-90456-default-administrative-password-in-bundled-inventory-management","title":"Default administrative password in bundled inventory-management component","severity":"info","exploited":false,"published_at":"2026-09-11T22:16:47.993+00:00","url":"https://junglewise.ai/threats/cve-2026-90456-default-administrative-password-in-bundled-inventory-management"},{"cve":"CVE-2026-90455","epss":0.0033,"slug":"cve-2026-90455-reverted-http-client-library-version-reintroduces-vulnerable","title":"Reverted HTTP client library version reintroduces vulnerable dependency","severity":"info","exploited":false,"published_at":"2026-09-11T22:16:47.873+00:00","url":"https://junglewise.ai/threats/cve-2026-90455-reverted-http-client-library-version-reintroduces-vulnerable"},{"cve":"CVE-2026-90452","cvss":7.4,"epss":0.0013,"slug":"cve-2026-90452-reverse-proxy-identity-provider-certificate-validation-bypass","title":"Reverse proxy identity provider certificate validation bypass","severity":"info","exploited":false,"published_at":"2026-09-11T22:16:47.473+00:00","url":"https://junglewise.ai/threats/cve-2026-90452-reverse-proxy-identity-provider-certificate-validation-bypass"},{"cve":"CVE-2026-90451","epss":0.0054,"slug":"cve-2026-90451-packet-analysis-component-hardcoded-default-signing-secret-in","title":"Packet-analysis component hardcoded default signing secret in example configuration","severity":"info","exploited":false,"published_at":"2026-09-11T22:16:47.343+00:00","url":"https://junglewise.ai/threats/cve-2026-90451-packet-analysis-component-hardcoded-default-signing-secret-in"},{"cve":"CVE-2026-90448","epss":0.0035,"slug":"cve-2026-90448-read-only-deployment-mode-access-control-bypass-in-api-routes","title":"Read-only deployment mode access control bypass in API routes","severity":"info","exploited":false,"published_at":"2026-09-11T22:16:46.95+00:00","url":"https://junglewise.ai/threats/cve-2026-90448-read-only-deployment-mode-access-control-bypass-in-api-routes"},{"cve":"CVE-2026-90445","cvss":6.5,"epss":0.0052,"slug":"cve-2026-90445-path-traversal-in-archive-extraction-file-upload","title":"Path traversal in archive extraction file upload","severity":"info","exploited":false,"published_at":"2026-09-11T22:16:46.51+00:00","url":"https://junglewise.ai/threats/cve-2026-90445-path-traversal-in-archive-extraction-file-upload"},{"cve":"CVE-2026-90443","epss":0.0056,"slug":"cve-2026-90443-reflected-xss-and-open-redirect-in-web-interface","title":"Reflected XSS and open redirect in web interface","severity":"info","exploited":false,"published_at":"2026-09-11T22:16:46.247+00:00","url":"https://junglewise.ai/threats/cve-2026-90443-reflected-xss-and-open-redirect-in-web-interface"},{"cve":"CVE-2026-78224","cvss":8.2,"epss":0.0044,"slug":"cve-2026-78224-xslt-transformer-step-xxe-injection","title":"XSLT Transformer Step XXE injection","severity":"high","exploited":false,"published_at":"2026-09-11T15:17:04.337+00:00","url":"https://junglewise.ai/threats/cve-2026-78224-xslt-transformer-step-xxe-injection"},{"cve":"CVE-2026-80469","cvss":8.3,"epss":0.0039,"slug":"cve-2026-80469-device-driver-package-arbitrary-code-execution-via-verification","title":"Device driver package arbitrary code execution via verification bypass","severity":"high","exploited":false,"published_at":"2026-09-11T09:17:20.833+00:00","url":"https://junglewise.ai/threats/cve-2026-80469-device-driver-package-arbitrary-code-execution-via-verification"},{"cve":"CVE-2026-82563","cvss":7.6,"epss":0.0024,"slug":"cve-2026-82563-camera-device-man-in-the-middle-impersonation-attack","title":"Camera device man-in-the-middle impersonation attack","severity":"high","exploited":false,"published_at":"2026-09-09T16:17:11.567+00:00","url":"https://junglewise.ai/threats/cve-2026-82563-camera-device-man-in-the-middle-impersonation-attack"},{"cve":"CVE-2026-14255","cvss":5.5,"epss":0.0011,"slug":"cve-2026-14255-autodesk-ifc-parser-uncontrolled-recursion-denial-of-service","title":"Autodesk IFC parser uncontrolled recursion denial of service","severity":"medium","exploited":false,"published_at":"2026-09-02T15:17:37.403+00:00","url":"https://junglewise.ai/threats/cve-2026-14255-autodesk-ifc-parser-uncontrolled-recursion-denial-of-service"},{"cve":"CVE-2026-56845","cvss":7.5,"epss":0.006,"slug":"cve-2026-56845-path-traversal-vulnerability-in-custom-sounds-endpoint","title":"Path traversal vulnerability in /custom-sounds/ endpoint","severity":"high","exploited":false,"published_at":"2026-08-04T01:16:19.66+00:00","url":"https://junglewise.ai/threats/cve-2026-56845-path-traversal-vulnerability-in-custom-sounds-endpoint"},{"cve":"CVE-2025-10898","cvss":7.8,"epss":0.0026,"slug":"cve-2025-10898-autodesk-products-out-of-bounds-write-in-model-file-parsing","title":"Autodesk products out-of-bounds write in MODEL file parsing","severity":"high","exploited":false,"published_at":"2025-12-16T00:16:01.007+00:00","url":"https://junglewise.ai/threats/cve-2025-10898-autodesk-products-out-of-bounds-write-in-model-file-parsing"},{"cve":"CVE-2025-10881","cvss":7.8,"epss":0.0028,"slug":"cve-2025-10881-autodesk-products-heap-based-overflow-in-catproduct-file-parsing","title":"Autodesk products heap-based overflow in CATPRODUCT file parsing","severity":"high","exploited":false,"published_at":"2025-12-16T00:15:59.493+00:00","url":"https://junglewise.ai/threats/cve-2025-10881-autodesk-products-heap-based-overflow-in-catproduct-file-parsing"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Autodesk 3ds Max","slug":"3ds-max","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/3ds-max"},{"name":"Autodesk AutoCAD","slug":"autocad","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/autocad"},{"name":"Autodesk FBX SDK","slug":"fbx-software-development-kit","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/fbx-software-development-kit"},{"name":"Autodesk AutoCAD LT","slug":"autocad-lt","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/autocad-lt"},{"name":"Autodesk DWG TrueView","slug":"dwg-trueview","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/dwg-trueview"},{"name":"Autodesk Revit","slug":"revit","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/revit"}],"technology":{"hub":true,"name":"Autodesk <UNKNOWN>","slug":"unknown","vendor":{"name":"Autodesk","slug":"autodesk","url":"https://junglewise.ai/threats/vendors/autodesk"},"aliases":[],"category":"cad/design-software","url":"https://junglewise.ai/threats/technologies/unknown"},"most_severe":[{"cve":"CVE-2026-25254","cvss":9.8,"epss":0.005,"slug":"cve-2026-25254-improper-authorization-leads-to-remote-code-execution-via","title":"SocketIO improper authorization remote code execution","severity":"critical","exploited":false,"published_at":"2026-09-22T10:17:08.583+00:00","url":"https://junglewise.ai/threats/cve-2026-25254-improper-authorization-leads-to-remote-code-execution-via"},{"cve":"CVE-2026-68070","cvss":8.8,"epss":0.0043,"slug":"cve-2026-68070-authentication-bypass-with-unauthenticated-root-command-execution","title":"Authentication bypass with unauthenticated root command execution","severity":"high","exploited":false,"published_at":"2026-09-15T21:16:42.253+00:00","url":"https://junglewise.ai/threats/cve-2026-68070-authentication-bypass-with-unauthenticated-root-command-execution"},{"cve":"CVE-2026-25255","cvss":8.8,"epss":0.0012,"slug":"cve-2026-25255-exposed-dangerous-function-lead-to-privilege-escalation-via-grpc","title":"gRPC server exposed dangerous function privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-22T10:17:08.847+00:00","url":"https://junglewise.ai/threats/cve-2026-25255-exposed-dangerous-function-lead-to-privilege-escalation-via-grpc"},{"cve":"CVE-2026-80469","cvss":8.3,"epss":0.0039,"slug":"cve-2026-80469-device-driver-package-arbitrary-code-execution-via-verification","title":"Device driver package arbitrary code execution via verification bypass","severity":"high","exploited":false,"published_at":"2026-09-11T09:17:20.833+00:00","url":"https://junglewise.ai/threats/cve-2026-80469-device-driver-package-arbitrary-code-execution-via-verification"},{"cve":"CVE-2026-78224","cvss":8.2,"epss":0.0044,"slug":"cve-2026-78224-xslt-transformer-step-xxe-injection","title":"XSLT Transformer Step XXE injection","severity":"high","exploited":false,"published_at":"2026-09-11T15:17:04.337+00:00","url":"https://junglewise.ai/threats/cve-2026-78224-xslt-transformer-step-xxe-injection"},{"cve":"CVE-2025-10881","cvss":7.8,"epss":0.0028,"slug":"cve-2025-10881-autodesk-products-heap-based-overflow-in-catproduct-file-parsing","title":"Autodesk products heap-based overflow in CATPRODUCT file parsing","severity":"high","exploited":false,"published_at":"2025-12-16T00:15:59.493+00:00","url":"https://junglewise.ai/threats/cve-2025-10881-autodesk-products-heap-based-overflow-in-catproduct-file-parsing"},{"cve":"CVE-2025-10898","cvss":7.8,"epss":0.0026,"slug":"cve-2025-10898-autodesk-products-out-of-bounds-write-in-model-file-parsing","title":"Autodesk products out-of-bounds write in MODEL file parsing","severity":"high","exploited":false,"published_at":"2025-12-16T00:16:01.007+00:00","url":"https://junglewise.ai/threats/cve-2025-10898-autodesk-products-out-of-bounds-write-in-model-file-parsing"},{"cve":"CVE-2026-82563","cvss":7.6,"epss":0.0024,"slug":"cve-2026-82563-camera-device-man-in-the-middle-impersonation-attack","title":"Camera device man-in-the-middle impersonation attack","severity":"high","exploited":false,"published_at":"2026-09-09T16:17:11.567+00:00","url":"https://junglewise.ai/threats/cve-2026-82563-camera-device-man-in-the-middle-impersonation-attack"},{"cve":"CVE-2026-56845","cvss":7.5,"epss":0.006,"slug":"cve-2026-56845-path-traversal-vulnerability-in-custom-sounds-endpoint","title":"Path traversal vulnerability in /custom-sounds/ endpoint","severity":"high","exploited":false,"published_at":"2026-08-04T01:16:19.66+00:00","url":"https://junglewise.ai/threats/cve-2026-56845-path-traversal-vulnerability-in-custom-sounds-endpoint"},{"cve":"CVE-2026-77165","cvss":6.5,"epss":0.0037,"slug":"cve-2026-77165-file-owners-were-unable-to-unlock-type-token-locks-placed-by","title":"Database file locking denial of service via TYPE_TOKEN locks","severity":"medium","exploited":false,"published_at":"2026-09-21T16:17:23.863+00:00","url":"https://junglewise.ai/threats/cve-2026-77165-file-owners-were-unable-to-unlock-type-token-locks-placed-by"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}