{"id":"CVE-2026-19781","title":"Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability","summary":"Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"Ashlar-Vellum","product":"Cobalt","affected":["Cobalt 1204.204"],"published":"2026-09-15","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:11:37.410","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19781","references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-587/","label":"zdi-disclosures@trendmicro.com"}],"tags":["nvd","cve.org"],"epss":0.00173,"epssPercentile":0.06997,"zeroDay":true,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-15T19:22:40.278547Z"},"ingestedAt":"2026-09-15T18:41:59.186Z","slug":"CVE-2026-19781","body":"## Overview\n\nAshlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of VS files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28173.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":68,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":25,"ransomware":0},"changes":[]}