NCSC-2026-0298 [1.00] [M/H] Vulnerabilities patched in Autodesk AutoCAD
Autodesk has patched multiple vulnerabilities in AutoCAD. The vulnerabilities are located in the way AutoCAD processes specially crafted DXF and DWG files. A heap-based overflow can lead to application crashes, unauthorized access to sensitive data, or execution of arbitrary code within the context of the application. Additionally, there are out-of-bounds read vulnerabilities that can similarly result in application crashes or leakage of sensitive information from memory. Exploitation requires that a user opens a malicious file, after which unintended memory access occurs that can compromise the integrity and confidentiality of the data.
CSIRTS triage
- What
- Heap-based overflow and out-of-bounds read vulnerabilities in DXF and DWG file processing can cause crashes, leak sensitive data, or execute arbitrary code.
- Who is affected
- AutoCAD users who open malicious DXF or DWG files.
- Urgency
- High urgency; arbitrary code execution is possible if a user opens a crafted file.
- Action
- Apply Autodesk's patches for CVE-2026-16463, CVE-2026-16465, and CVE-2026-17550.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch AutoCAD
Get an email when a new AutoCAD advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0298
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-164630.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-164650.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175500.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16463 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16465 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17550 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Autodesk AutoCAD: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-17550: A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-…nvd
- mediumCVE-2026-16465: A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-…nvd
- highCVE-2026-16463: A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based O…nvd
Recent advisories for Autodesk AutoCAD
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Autodesk AutoCAD and Civil 3D: Multiple vulnerabilitiescert-bund · 2026-08-07
- medium[NEW] [medium] Autodesk AutoCAD: Multiple vulnerabilitiescert-bund · 2026-07-30
- mediumCVE-2026-17550: A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-…nvd · 2026-07-29
- mediumCVE-2026-16465: A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-…nvd · 2026-07-29
- highCVE-2026-16463: A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based O…nvd · 2026-07-29
More from NCSC-NL Advisories
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter2026-08-15
- unknownNCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM2026-08-14
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager2026-08-13
- unknownNCSC-2026-0297 [1.00] [M/H] Vulnerabilities patched in GitLab Enterprise Edition and Community Edition2026-08-13