SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-64198

HIGH · CVSS 7.8 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

DASYLab is vulnerable to an out-of-bounds read due to inadequate validation of user-supplied data, which can lead to reading beyond the allocated heap buffer during file handling. This vulnerability can be exploited by tricking a user into opening a specially crafted .DSB file, potentially allowing an attacker to access sensitive information or execute arbitrary code. Organizations using DASYLab versions prior to 2026.0.0 should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-64198
Severity
HIGH
CVSS
7.8
EPSS
0.12%

Original NVD Description

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.