Zero Day Initiative disclosed two zero-day vulnerabilities in Labcenter Electronics Proteus that can lead to remote code execution when the application parses a malicious PDSPRJ project file. The flaws are tracked as CVE-2026-5493 (ZDI-26-255, ZDI-CAN-25718) and CVE-2026-5496 (ZDI-26-254, ZDI-CAN-25717), with both assigned a CVSS 7.8 score. One issue stems from an out-of-bounds write, while the other is caused by type confusion due to improper validation of user-supplied data.
Exploitation requires user interaction, such as opening a crafted file or visiting a malicious page, after which arbitrary code may run in the context of the current process. ZDI said it reported the issues to the vendor in April 2025, but Labcenter later indicated the software and installer were no longer in production. After seeking an end-of-life announcement and notifying the vendor of its intent to disclose, ZDI published both cases as zero-day advisories.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-06, ZDI published an advisory for Labcenter Electronics Proteus flaw CVE-2026-5494 / ZDI-26-256, a PDSPRJ file parsing out-of-bounds write that can lead to remote code execution. The issue requires user interaction, such as opening a malicious file or visiting a malicious page, and was disclosed as a zero-day after the vendor said the affected software was no longer in production.
On April 6, 2026, ZDI published zero-day advisories for two Labcenter Electronics Proteus vulnerabilities in PDSPRJ file parsing. The issues, CVE-2026-5493 and CVE-2026-5496, can allow arbitrary code execution if a user opens a malicious file or visits a malicious page.
After receiving the reports, the vendor told ZDI that the affected Proteus software and installer were no longer in production. ZDI then sought an end-of-life announcement and notified the vendor of its intent to disclose.
Zero Day Initiative reported a Labcenter Electronics Proteus remote code execution vulnerability involving PDSPRJ file parsing to the vendor. The flaw was later tracked as CVE-2026-5493 / ZDI-26-255 and stemmed from an out-of-bounds write.
In April 2025, Zero Day Initiative reported another Labcenter Electronics Proteus remote code execution vulnerability involving PDSPRJ file parsing. The flaw was later tracked as CVE-2026-5495 / ZDI-26-257 and was caused by an out-of-bounds write due to improper validation of user-supplied data.
In April 2025, ZDI also reported a second Proteus PDSPRJ file parsing remote code execution issue to Labcenter Electronics. This separate flaw was later tracked as CVE-2026-5496 / ZDI-26-254 and involved a type confusion condition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
zerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.