CVE-2026-32927

7.8

Fuji Electric · V-SFT

V-SFT versions 6.2.10.0 and prior are susceptible to an out-of-bounds read vulnerability in the VS6MemInIF module, which may lead to information disclosure when processing a crafted V7 file.

Executive summary

A critical out-of-bounds read vulnerability in Fuji Electric V-SFT allows attackers to achieve unauthorized information disclosure through the processing of malicious V7 files.

Vulnerability

The software contains an out-of-bounds read flaw within the VS6MemInIF!set_temp_type_default function. This vulnerability can be triggered by an attacker without specific authentication by enticing a user to open a crafted V7 file within the application.

Business impact

The exploitation of this vulnerability can lead to significant information disclosure, potentially exposing sensitive data processed or stored by the V-SFT software. Given the CVSS score of 7.8, this flaw presents a high risk to operational integrity and data confidentiality. Unauthorized access to internal information could lead to further system compromise or the exposure of proprietary manufacturing configurations.

Remediation

Immediate Action: Users must update V-SFT to a version beyond 6.2.10.0 as provided by the vendor in their official security advisory.

Proactive Monitoring: Security teams should monitor workstation and server logs for abnormal application crashes or unexpected file access patterns associated with V-SFT.

Compensating Controls: Implement strict file validation policies and restrict the opening of untrusted or externally sourced V7 files until the software has been patched.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

This vulnerability represents a high-severity risk to environments utilizing Fuji Electric V-SFT software. Organizations are urged to prioritize the application of vendor-supplied patches to remediate the out-of-bounds read condition. Until updates are applied, users should exercise extreme caution when handling V7 files from untrusted sources to prevent potential information disclosure.

More Fuji Electric CVEs

Sources