CVE-2026-3476: 3ds Solidworks

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code on the user's machine while opening a specially crafted file.

Affected products

  • 3ds Solidworks: from 2025, before 2026 (fixed in 2026); version 2026 only

Published 2026-03-16. Last modified 2026-06-17.