# Labcenter Proteus 9 flaws risk code execution

Published: 2026-07-07 · Severity: medium · Sectors: energy, healthcare, defense, transportation, telecommunications, manufacturing
Canonical: https://vorant.io/reports/395ccedb-08b8-578a-919d-1d1c2c73863d/labcenter-proteus-9-flaws-risk-code-execution

> Three memory-corruption vulnerabilities in Labcenter Proteus 9 could let attackers execute arbitrary code via crafted files, but no public exploitation is known.

CISA has published an ICS advisory covering three vulnerabilities in Labcenter Electronics' Proteus 9 (build 9.1_SP4_Build_42914), an electronic design automation tool used across multiple critical infrastructure sectors worldwide. The flaws include an out-of-bounds write (CVE-2026-42953), a stack-based buffer overflow (CVE-2026-49033), and a use-after-free condition triggered while parsing specially crafted files (CVE-2026-42958). All three could allow arbitrary code execution in the context of the current process if a victim opens a malicious file.

The vulnerabilities were responsibly disclosed to CISA by researcher Michael Heinzl. Labcenter has released version 9.2 SP0 to remediate the issues, and CISA recommends organizations update immediately, follow standard network segmentation and remote-access hardening practices, and remain vigilant against phishing-based delivery of malicious files. CISA notes the vulnerabilities are not exploitable remotely and there is no evidence of active exploitation at this time.

Given the lack of remote exploitability and absence of in-the-wild abuse, this represents a routine vendor-patch advisory rather than an active threat, though organizations using Proteus for PCB/circuit design in sectors like energy, healthcare, and defense should apply the update to reduce local exploitation risk via malicious project files.

## Mentioned in this report

- Vulnerabilities: CVE-2026-42953, CVE-2026-42958, CVE-2026-49033

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/395ccedb-08b8-578a-919d-1d1c2c73863d/labcenter-proteus-9-flaws-risk-code-execution.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
