ShellCodeX vulnerability brief
MEDIUM
Received
CVE-2026-16782
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Published 24 Aug 2026, 21:16 UTC
Last modified 24 Aug 2026, 21:16 UTC
SCX
ShellCodeX risk assessment
Planned remediation priority based on exploitation evidence, CVSS conditions and affected-product data.
PriorityEvidenceDecision use
Planned
The vulnerable path is reachable over a network.
Validate against your asset inventory and vendor advisory.
Planned
Exploitation does not require prior privileges.
Validate against your asset inventory and vendor advisory.
01
Attack profile
The conditions required to exploit this vulnerability and its potential impact.
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
02
Affected products
Product applicability statements supplied with the NVD record.
NVD has not published structured affected-product data for this record.
03
Weakness classification
CWE categories help security teams group the underlying software weakness.
04
Source references
External advisories, patches and technical reports attached to this CVE record.