{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/office-application/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-11803"},{"cvss":7.8,"id":"CVE-2026-7406"},{"cvss":7.8,"id":"CVE-2026-1289"},{"cvss":7.8,"id":"CVE-2026-8325"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Revit 2026","Revit 2027","Revit (\u003c 2027.2.0)","Revit (\u003c 2026.5.0)","Revit (\u003c 2027.1.0, \u003c 2026.5.0, \u003c 2024.3.5)","AutoCAD (\u003c 2027.1.0)","AutoCAD LT (\u003c 2027.1.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cve","office-application"],"_cs_type":"advisory","_cs_vendors":["Autodesk"],"content_html":"\u003cp\u003eAutodesk has disclosed a high-severity vulnerability (CVE-2026-11803) affecting multiple versions of Autodesk Revit. The issue is rooted in an out-of-bounds read vulnerability occurring during the parsing of maliciously crafted PDF files. Successful exploitation requires user interaction, where an attacker must entice a victim to open a specially crafted PDF document within the Revit application. If successful, the vulnerability may allow a remote attacker to trigger an application crash, access sensitive process memory, or achieve arbitrary code execution within the context of the user running the Revit process. Organizations using Revit 2026 and 2027 should prioritize patching to the recommended versions to remediate the flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-11803 allows for potential full system compromise within the security context of the user executing the Revit process. This could lead to the exfiltration of sensitive design data, unauthorized access to internal resources, or further lateral movement within the network. Users in the engineering, architecture, and construction sectors are primary targets due to the industry-specific nature of the software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply security updates immediately for Autodesk Revit 2026 and 2027 to the versions specified in the Autodesk security advisory ADSK-SA-2026-0011.\u003c/li\u003e\n\u003cli\u003eAdvise end-users to exercise caution when handling unsolicited PDF files, especially those sent to recipients who utilize Revit for design workflows.\u003c/li\u003e\n\u003cli\u003eMonitor endpoint process behavior for unexpected child processes spawned by Revit.exe, as this may indicate an attempt to gain code execution after an initial crash or memory read.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T23:33:30Z","date_published":"2026-08-06T23:29:49Z","id":"https://feed.craftedsignal.io/briefs/2026-08-revit-pdf-vulnerability/","summary":"Autodesk Revit contains an out-of-bounds read vulnerability in its PDF parsing engine that can be exploited for arbitrary code execution or information disclosure.","title":"Arbitrary Code Execution in Autodesk Revit via Malicious PDF","url":"https://feed.craftedsignal.io/briefs/2026-08-revit-pdf-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Office-Application","version":"https://jsonfeed.org/version/1.1"}