CVE-2025-65086: Out-of-bounds write in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share
Published May 12, 2026
·Updated
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary code when a specially crafted VC6 file is being parsed.
Affected Software
10 affected components
Ashlar-Vellum Cobalt<=12.6.1204.216
Ashlar-Vellum Xenon<=12.6.1204.216
Ashlar-Vellum Argon<=12.6.1204.216
Ashlar-Vellum Lithium<=12.6.1204.216
Ashlar-Vellum Cobalt Share<=12.6.1204.216
Ashlar Argon<=12.6.1204.216
Ashlar Cobalt<=12.6.1204.216
Ashlar Cobalt Share<=12.6.1204.216
Ashlar Lithium<=12.6.1204.216
Ashlar Xenon<=12.6.1204.216
Remediation
Information
Ashlar-Vellum recommends users update to build 12.6.1204.217 and later.
Event History
May 12, 2026
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65086?
CVE-2025-65086 has a critical severity level as it allows an attacker to execute arbitrary code.
2
How do I fix CVE-2025-65086?
To mitigate CVE-2025-65086, update Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share to version 12.6.1204.217 or later.
3
Which versions are affected by CVE-2025-65086?
CVE-2025-65086 affects Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and earlier.
4
What kind of vulnerability is CVE-2025-65086?
CVE-2025-65086 is categorized as an out-of-bounds write vulnerability.
5
Who is the vendor for the software affected by CVE-2025-65086?
The vendor for the software affected by CVE-2025-65086 is Ashlar-Vellum.