CVE-2016-2536: Google Sketchup

High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Multiple use-after-free vulnerabilities in SAP 3D Visual Enterprise Viewer allow remote attackers to execute arbitrary code via a crafted SketchUp document. NOTE: the primary affected product may be SketchUp.

Affected products

  • Google Sketchup: any version
  • SAP 3d Visual Enterprise Viewer: any version

Published 2016-02-22. Last modified 2026-06-17.