PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-65086 Ashlar-Vellum CVE debrief

CVE-2025-65086 is a high-severity out-of-bounds write issue in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share. According to CISA’s advisory, parsing a specially crafted VC6 file can allow arbitrary code execution. Ashlar-Vellum’s mitigation is to update to build 12.6.1204.217 or later. Because exploitation is tied to file parsing and the CVSS vector includes user interaction, organizations should treat this as a priority for any workstation or environment that opens untrusted VC6 content.

Vendor
Ashlar-Vellum
Product
Cobalt
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-11-25
Original CVE updated
2026-05-12
Advisory published
2025-11-25
Advisory updated
2026-05-12

Who should care

Administrators, engineers, and users running Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, or Cobalt Share—especially on systems that receive or open VC6 files from external sources.

Technical summary

CISA describes an out-of-bounds write in affected Ashlar-Vellum products version 12.6.1204.216 and prior. The issue occurs during VC6 file parsing and may permit arbitrary code execution. The supplied CVSS 3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a local attack path with user interaction required and potentially severe confidentiality, integrity, and availability impact. CISA’s Update A (2026-05-12) revised the affected versions and mitigation guidance, and the recommended fixed build is 12.6.1204.217 or later.

Defensive priority

High. The vulnerability is rated HIGH, can lead to code execution, and is reachable through common file-opening workflows that may involve untrusted content.

Recommended defensive actions

  • Update Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share to build 12.6.1204.217 or later.
  • Identify systems that process VC6 files and prioritize them for patching.
  • Treat VC6 files from untrusted or external sources as suspicious and restrict handling where possible.
  • Limit who can open externally supplied project files on affected workstations.
  • Review endpoint protections and user guidance for file-based attack paths, including safe handling of unexpected attachments or project files.

Evidence notes

Source corpus states: affected versions are 12.6.1204.216 and prior; the issue is an out-of-bounds write during parsing of a specially crafted VC6 file; arbitrary code execution is possible; the mitigation is to update to 12.6.1204.217 and later. The published date is 2025-11-25T07:00:00Z and the advisory was revised on 2026-05-12T06:00:00Z in Update A.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-65086 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-65086

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-65086 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-65086

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-329-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.