CVE-2026-5495Disclosure(labcenter / proteus)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch labcenter proteus systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDSPRJ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25720.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • proteus

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-04-06); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
proteus

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-04-06: 5Mentions · 2026-04-07: 1Mentions · 2026-04-08: 1Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-06: 4Patch / Workaround · 2026-04-06: 5Technical Details · 2026-04-06: 5Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-11: 104-0604-0704-0804-11
Signal classification2 categories
Disclosure
787.5%
General
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-065
Disclosure5
2026-04-071
Disclosure1
2026-04-081
Disclosure1
2026-04-111
General1
Full discourse8 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-257|CVE-2026-5495] (0Day) Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (CVSS 7.8; Credit: Andrea Micalizzi aka rgod (@rgod777)) https://www.zerodayinitiative.com/advisories/ZDI-26-257/

    Post summary

    A new 0‑day CVE (CVE‑2026‑5495) affecting Labcenter Electronics Proteus was disclosed, describing an out‑of‑bounds write that allows remote code execution and assigning a CVSS score of 7.8, with no PoC, patch or exploitation evidence in the text.

    00041669
    5.5K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Labcenter Proteus PDSPRJ Out-of-Bounds Write Remote Code Execution (CVE-2026-5495) 🆔 **CVE-2026-5495** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Proteus (unspecified versions) 🫨 **Attack Vectors:** - Opening a crafted PDSPRJ file (user interaction required) - Visiting a webpage that triggers processing of a crafted PDSPRJ file 📝 **Summary:** A crafted PDSPRJ file can trigger an out‑of‑bounds write in Labcenter Proteus file processing, allowing memory corruption and remote code execution in the context of the affected process. The vendor states the product/installer is out of production and no fixes have been published, so affected installs should be treated as high risk. 📈 **Impact Scope:** Allows memory corruption leading to remote code execution; impacts confidentiality, integrity, and availability. Vendor states software/installer are out of production and no fixes were published. 🛡️ **Recommended Actions:** - Do not open PDSPRJ files from untrusted sources - Remove or isolate Labcenter Proteus installations where possible - Apply application whitelisting and restrict execution privileges - Block/monitor email/web delivery of PDSPRJ files and monitor hosts for anomalous behavior 🪢 **Related Resources:** - http://www.zerodayinitiative.com/advisories/ZDI-26-257/ - https://www.cve.org/CVERecord?id=CVE-2026-5495 🏷 **Tags:** #Cybersecurity #LabcenterProteus #CVE2026-5495

    Post summary

    The post announces CVE-2026-5495, an out‑of‑bounds write in Labcenter Proteus that allows remote code execution, and urges users to apply mitigations since no patch or fix is available.

    0001043
    273 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5495 Out-Of-Bounds Write Remote Code Execution in Labcenter Electronics Proteus PDSPRJ https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5495

    Post summary

    The CVE-2026-5495 pertains to an Out-Of-Bounds Write Remote Code Execution flaw in Labcenter Electronics Proteus PDSPRJ, but the provided text offers only the vulnerability designation without details on exploitation, patches, or active attacks.

    0000048
    4.0K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2026-5495) #CVE20265495 #CyberSecurity #LabcenterElectronics #RemoteCodeExecutionVulnerability https://www.systemtek.co.uk/?p=49032 https://t.co/UUgYXpG0bR

    Post summary

    The tweet announces CVE‑2026‑5495, an out‑of‑bounds write RCE in Labcenter Electronics' Proteus PDSPRJ file parser, linking to an article with further details.

    0000052
    1.8K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Labcenter Electronics Proteus PDSPRJ File Parsing Remote Code Execution Vulnerabilities (Out-of-Bounds Write & Type Confusion) 🆔 **CVE-2026-5495** | 📊 CVSS: 7.8 (High 🟠) 🆔 **CVE-2026-5496** | 📊 CVSS: 7.8 (High 🟠) 🆔 **CVE-2026-5493** | 📊 CVSS: 7.8 (High 🟠) 🆔 **CVE-2026-5494** | 📊 CVSS: 7.8 (High 🟠) 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Proteus PDSPRJ parsing (unspecified; EoL) 🫨 **Attack Vectors:** - User opening crafted PDSPRJ file (user interaction required) - Visiting a malicious webpage that triggers file parsing (user interaction required) 📝 **Summary:** Multiple PDSPRJ file parsing flaws (out-of-bounds write and type confusion) in Labcenter Proteus allow remote code execution in the context of the running process when a user opens a crafted file or visits a malicious page. Proteus is EoL and no vendor patches are available, increasing risk for any remaining installations. 📈 **Impact Scope:** Remote code execution with high impact to confidentiality, integrity, and availability; exploitation requires user interaction and is limited by the need to open/trigger crafted PDSPRJ content. 🛡️ **Recommended Actions:** - Do not open PDSPRJ files from untrusted sources - Isolate systems running Proteus and restrict file exchange - Replace EoL Proteus installations with maintained alternatives - Apply host-based mitigations (application whitelisting, least privilege) 🪢 **Related Resources:** - http://www.zerodayinitiative.com/advisories/ZDI-26-257/ - https://www.cve.org/CVERecord?id=CVE-2026-5495 🏷 **Tags:** #Cybersecurity #Proteus #Labcenter

    Post summary

    The advisory discloses four high‑impact CVEs affecting Proteus PDSPRJ parsing, details the vulnerability mechanics, notes no vendor patches, and recommends mitigation steps.

    0000038
    273 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Labcenter Electronics Proteus PDSPRJ File Parsing Remote Code Execution Vulnerabilities (CVE-2026-5493, CVE-2026-5494, CVE-2026-5495, CVE-2026-5496) 📅 **Timeline:** Disclosure: 2026-04-06, Patch: Not Available 🆔 **CVE-2026-5493** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-5494** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-5495** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-5496** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 🫨 **Attack Vectors:** - User opens crafted PDSPRJ file - User visits a malicious web page that triggers PDSPRJ processing 📝 **Summary:** Multiple PDSPRJ file parsing flaws in Labcenter Proteus (CVE-2026-5493–5496) can cause memory corruption leading to remote code execution when a user opens a crafted PDSPRJ or visits a malicious page. Exploitation requires user interaction and impact depends on the privileges of the Proteus process. 📈 **Impact Scope:** Memory corruption leading to remote code execution in the context of the affected process when a user opens a crafted PDSPRJ file or visits a malicious page; scope depends on user/application privileges. 🛡️ **Recommended Actions:** - Do not open PDSPRJ files from untrusted sources - Apply vendor patches if and when released 🪢 **Related Resources:** - http://www.zerodayinitiative.com/advisories/ZDI-26-257/ - https://www.cve.org/CVERecord?id=CVE-2026-5493 🏷 **Tags:** #Cybersecurity #Labcenter #Proteus

    Post summary

    Labcenter Electronics Proteus PDSPRJ file parsing vulnerabilities (CVE‑2026‑5493–5496) were disclosed with high CVSS scores, noting memory corruption that can lead to remote code execution; no patches exist yet, and no active exploitation has been reported.

    0000032
    273 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Labcenter Electronics Proteus PDSPRJ File Parsing Remote Code Execution Vulnerabilities (CVE-2026-5493, CVE-2026-5494, CVE-2026-5495, CVE-2026-5496) 🆔 **CVE-2026-5493** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-5494** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-5495** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-5496** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Not specified (vendor reported software and installer are End-of-Life) 🔧 **Fixed Versions:** None (vendor EoL; no fixes available) 🫨 **Attack Vectors:** - Opening a specially crafted PDSPRJ file (local file processing) - Visiting a malicious page that causes Proteus to process a crafted PDSPRJ file (user interaction required) 📝 **Summary:** Multiple PDSPRJ parsing vulnerabilities (out-of-bounds write and type confusion) in Labcenter Proteus allow arbitrary code execution when a user opens a crafted project file or a page triggers processing. Exploitation yields code execution in the Proteus process and can lead to wider system compromise depending on privileges; vendor has declared the product EoL with no fixes available. 📈 **Impact Scope:** Successful exploitation allows arbitrary code execution in the context of the Proteus process (high confidentiality, integrity, availability impact). Depending on host privileges, this may lead to broader system compromise or persistence. 🛡️ **Recommended Actions:** - Immediately cease use or isolate systems running Proteus; consider removal since product is EoL - Block/quarantine PDSPRJ files at mail gateways and endpoints - Disable automatic processing/opening of PDSPRJ files and remove associated file handlers - Enforce least privilege and run Proteus only in sandboxed/isolated environments if unavoidable - Deploy/verify EDR detections, restrict network access from affected hosts, and monitor for compromise - Apply vendor patches if released and consult ZDI advisories for indicators 🪢 **Related Resources:** - http://www.zerodayinitiative.com/advisories/ZDI-26-257/ - https://www.cve.org/CVERecord?id=CVE-2026-5493 🏷 **Tags:** #Cybersecurity #Proteus #Labcenter

    Post summary

    Labcenter Electronics Proteus has been disclosed with multiple high‑severity PDSPRJ parsing vulnerabilities (CVE‑2026‑5493‑5496). The advisory outlines the technical details and recommends mitigating actions, as no patches are available.

    0000034
    273 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Labcenter Electronics Proteus PDSPRJ File Parsing Remote Code Execution (Multiple CVEs) 🆔 **CVE-2026-5493** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-5494** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-5495** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-5496** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 🫨 **Attack Vectors:** - Opening a malicious PDSPRJ file (user interaction) - Visiting a malicious page (user interaction) 📝 **Summary:** Multiple PDSPRJ parsing flaws (CVE-2026-5493–5496) in Labcenter Proteus allow arbitrary code execution via out-of-bounds writes and a type confusion when a user opens a crafted PDSPRJ or visits a malicious page. Vendor states the software/installer are EOL, so patches may be limited—prioritize isolation and blocking of PDSPRJ files. 📈 **Impact Scope:** Successful exploitation allows arbitrary code execution with the privileges of the Proteus process; issues include out-of-bounds writes and a type confusion during PDSPRJ parsing. Vendor noted software/installer no longer in production which may limit available patches. 🛡️ **Recommended Actions:** - Do not open PDSPRJ files from untrusted sources - Block or quarantine PDSPRJ attachments at mail gateways and endpoints - Isolate or remove EOL Proteus installations where feasible - Apply vendor patches if/when available and follow ZDI advisories; monitor Proteus process activity with EDR 🪢 **Related Resources:** - http://www.zerodayinitiative.com/advisories/ZDI-26-257/ - https://www.cve.org/CVERecord?id=CVE-2026-5495 🏷 **Tags:** #Cybersecurity #Proteus #ZDI

    Post summary

    Labcenter Proteus PDSPRJ parsing flaws (CVE‑2026‑5493‑5496) enable remote code execution via out‑of‑bounds writes and type confusion. No active exploitation is reported; mitigations include blocking PDSPRJ files, isolating EOL installations, and applying vendor patches when available.

    0000029
    273 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applabcenterproteus8.17--

Explore more