Digilent has addressed two remote code execution vulnerabilities in DASYLab that were publicly disclosed by the Zero Day Initiative as ZDI-26-233 and ZDI-26-234, mapped to CVE-2026-0955 and CVE-2026-0956. Both flaws stem from improper validation of user-supplied data while parsing DSA files, leading to an out-of-bounds read that can be leveraged for arbitrary code execution in the context of the current process.
Exploitation requires user interaction, including opening a malicious file or visiting a malicious page, and each issue carries a CVSS 7.8 severity rating. Digilent released updates to remediate the vulnerabilities, and both disclosures credit Rocco Calvi of TecSecurity for reporting the issues.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On March 30, 2026, the Zero Day Initiative published advisories ZDI-26-233 and ZDI-26-234 for Digilent DASYLab, disclosing CVE-2026-0955 and CVE-2026-0956. Both issues were credited to Rocco Calvi of TecSecurity and carried CVSS scores of 7.8.
Digilent issued updates to remediate two remote code execution vulnerabilities in DASYLab involving improper validation during DSA file parsing. The flaws, later assigned CVE-2026-0955 and CVE-2026-0956, could lead to out-of-bounds reads and arbitrary code execution if a user opened a malicious file or visited a malicious page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.