PatchSiren cyber security CVE debrief
CVE-2025-65086 Ashlar-Vellum CVE debrief
CVE-2025-65086 is a high-severity out-of-bounds write issue in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share. According to CISA’s advisory, parsing a specially crafted VC6 file can allow arbitrary code execution. Ashlar-Vellum’s mitigation is to update to build 12.6.1204.217 or later. Because exploitation is tied to file parsing and the CVSS vector includes user interaction, organizations should treat this as a priority for any workstation or environment that opens untrusted VC6 content.
- Vendor
- Ashlar-Vellum
- Product
- Cobalt
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-11-25
- Original CVE updated
- 2026-05-12
- Advisory published
- 2025-11-25
- Advisory updated
- 2026-05-12
Who should care
Administrators, engineers, and users running Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, or Cobalt Share—especially on systems that receive or open VC6 files from external sources.
Technical summary
CISA describes an out-of-bounds write in affected Ashlar-Vellum products version 12.6.1204.216 and prior. The issue occurs during VC6 file parsing and may permit arbitrary code execution. The supplied CVSS 3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a local attack path with user interaction required and potentially severe confidentiality, integrity, and availability impact. CISA’s Update A (2026-05-12) revised the affected versions and mitigation guidance, and the recommended fixed build is 12.6.1204.217 or later.
Defensive priority
High. The vulnerability is rated HIGH, can lead to code execution, and is reachable through common file-opening workflows that may involve untrusted content.
Recommended defensive actions
- Update Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share to build 12.6.1204.217 or later.
- Identify systems that process VC6 files and prioritize them for patching.
- Treat VC6 files from untrusted or external sources as suspicious and restrict handling where possible.
- Limit who can open externally supplied project files on affected workstations.
- Review endpoint protections and user guidance for file-based attack paths, including safe handling of unexpected attachments or project files.
Evidence notes
Source corpus states: affected versions are 12.6.1204.216 and prior; the issue is an out-of-bounds write during parsing of a specially crafted VC6 file; arbitrary code execution is possible; the mitigation is to update to 12.6.1204.217 and later. The published date is 2025-11-25T07:00:00Z and the advisory was revised on 2026-05-12T06:00:00Z in Update A.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-65086 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-65086
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-65086 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-65086
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-329-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.