CVE-2026-1288: Autodesk Revit

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.

Affected products

  • Autodesk Revit: from 2024, before 2024.3.5 (fixed in 2024.3.5); from 2025, before 2025.4.5 (fixed in 2025.4.5); from 2026, before 2026.4.1 (fixed in 2026.4.1); from 2027, before 2027.1 (fixed in 2027.1)

Published 2026-06-17. Last modified 2026-06-29.