Fuji Electric V-SFT versions 6.2.10.0 and earlier were reported with two vulnerabilities triggered by opening a crafted V7 file. CVE-2026-32928 is a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem that can lead to arbitrary code execution, while CVE-2026-32929 is an out-of-bounds read in VS6ComFile!get_macro_mem_COM that can expose information from the affected product.
Both issues were reported through JPCERT/CC and classified under CWE-121 and CWE-125, respectively, with severity assessments published using CVSS v3.1 and CVSS v4.0. The vulnerabilities affect engineering software used in industrial environments, and vendor and advisory references were published by Fuji Electric and JVN, indicating that organizations using V-SFT should identify affected installations and prioritize remediation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
JPCERT/CC received a report of CVE-2026-32927 on 2026-04-01 affecting V-SFT 6.2.10.0 and earlier. The flaw is an out-of-bounds read in VS6MemInIF!set_temp_type_default triggered by opening a crafted V7 file, which may allow information disclosure.
JPCERT/CC recorded CVE-2026-32926 on 2026-04-01 affecting V-SFT 6.2.10.0 and earlier. The flaw is an out-of-bounds read in VS6ComFile!load_link_inf triggered by opening a crafted V7 file, which may allow information disclosure.
JPCERT/CC received a report of CVE-2026-32925 on 2026-04-01 affecting V-SFT 6.2.10.0 and earlier. The flaw is a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom that can be triggered by opening a crafted V7 file and may allow arbitrary code execution.
JPCERT/CC received a report of CVE-2026-32929 affecting V-SFT 6.2.10.0 and earlier on 2026-04-01. The vulnerability is an out-of-bounds read in VS6ComFile!get_macro_mem_COM triggered by opening a crafted V7 file, which may lead to information disclosure.
JPCERT/CC received a report of CVE-2026-32928 affecting V-SFT 6.2.10.0 and earlier on 2026-04-01. The flaw is a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem that can be triggered by opening a crafted V7 file and may allow arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.