# CVE-2026-85217

## Summary

- **CVE ID:** CVE-2026-85217
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- **CWE:** CWE-15
- **Published:** Sep 10, 2026
- **Last Modified:** Sep 11, 2026

## Description

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.

## Affected Products

- Autodesk — Fusion (2705.0.0)

## References

- [CNA](https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0016)
- [CNA](https://dl.appstreaming.autodesk.com/production/installers/Fusion%20Client%20Downloader.exe)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._