CVE-2026-4345: Autodesk Fusion

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.

Affected products

  • Autodesk Fusion: before 2702.1.47 (fixed in 2702.1.47)

Published 2026-04-14. Last modified 2026-06-17.