ShellCodeX vulnerability brief
MEDIUM
EPSS 0.1%
Received
CVE-2026-16781
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service.
Published 24 Aug 2026, 21:16 UTC
Last modified 25 Aug 2026, 15:16 UTC
SCX
ShellCodeX risk assessment
Planned remediation priority based on exploitation evidence, CVSS conditions and affected-product data.
PriorityEvidenceDecision use
Planned
EPSS estimates a 0.10% near-term exploitation probability.
Validate against your asset inventory and vendor advisory.
Planned
Exploitation does not require prior privileges.
Validate against your asset inventory and vendor advisory.
01
Attack profile
The conditions required to exploit this vulnerability and its potential impact.
Attack vector
Local
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
02
Affected products
Product applicability statements supplied with the NVD record.
NVD has not published structured affected-product data for this record.
03
Weakness classification
CWE categories help security teams group the underlying software weakness.
04
Source references
External advisories, patches and technical reports attached to this CVE record.