<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:autodesk:fusion_desktop:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aautodeskfusion_desktop/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 15:10:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aautodeskfusion_desktop/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Proxy Configuration via Autodesk Fusion Desktop Add-ins</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85217/</link><pubDate>Thu, 10 Sep 2026 15:10:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85217/</guid><description>CVE-2026-85217 allows a malicious Autodesk Fusion add-in to silently modify network proxy settings, enabling traffic interception and potential sensitive data exfiltration.</description><content:encoded><![CDATA[<p>CVE-2026-85217 is a security vulnerability in Autodesk Fusion Desktop that permits a maliciously crafted add-in to modify persistent network proxy settings without requiring user notification or consent. This vulnerability occurs during the execution of an installed add-in, allowing an attacker to intercept, redirect, or inspect authenticated network traffic generated by the application. Because the proxy modification can be performed silently, an attacker can position themselves as a Man-in-the-Middle (MitM) for Fusion traffic. This facilitates the theft of session tokens, credentials, or proprietary design data transmitted during the user's session. The scope of this threat is significant as it affects the confidentiality of intellectual property managed within the Fusion platform. Defenders should be aware that the primary vector is the installation and execution of untrusted third-party extensions within the Fusion ecosystem.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the redirection of authenticated application traffic to an attacker-controlled endpoint. This results in the exposure of sensitive design information and potential credential harvesting for the authenticated user's Autodesk account. The impact is primarily focused on the confidentiality of design data and the integrity of user sessions within the Autodesk Fusion Desktop environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the implementation of organizational policies that restrict the installation of third-party add-ins for Autodesk Fusion to only those that have been vetted and cryptographically signed by trusted developers. Monitor endpoints for unauthorized modifications to global or application-specific proxy configurations, particularly those occurring in proximity to the execution of Autodesk Fusion or its associated subprocesses. Ensure all Fusion Desktop instances are updated to the latest vendor-supplied version to remediate the underlying lack of validation for proxy modification requests.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>