Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Remote Code Execution in OriginLab Origin Viewer (CVE‑2026‑19886) via Malicious OGM Files

OriginLab’s Origin Viewer is vulnerable to CVE‑2026‑19886, a memory‑corruption bug that lets remote attackers execute code when a user opens a crafted OGM file. The flaw scores 7.8 (High) and is patched in version 10.4.0.25. For SOC 2‑ready organizations, the incident underscores the need for robust control mapping and continuous evidence of patch management.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in OriginLab Origin Viewer (CVE‑2026‑19886) via Malicious OGM Files

What It Is — OriginLab’s Origin Viewer contains a memory‑corruption flaw in its OGM file parser that allows an attacker to execute arbitrary code on the victim’s machine. The issue stems from insufficient validation of user‑supplied data, leading to a heap‑corruption condition.

Exploitability — A remote attacker can trigger the flaw by convincing a user to open a crafted OGM file or visit a malicious web page that serves one. The CVSS v3.1 base score is 7.8 (High) with vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. No public exploit is known, but the low attack complexity and high impact make it a serious concern.

Affected Products — OriginLab Origin Viewer (all versions prior to 10.4.0.25).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping: The vulnerability highlights a gap in your change‑management and software‑validation controls (SOC 2 CC6.1). Mapping this gap to your control library demonstrates due diligence.
  • Continuous Evidence: Demonstrating that you have a process to monitor vendor‑supplied patches and capture remediation evidence satisfies the “monitoring” and “evidence” criteria of SOC 2’s Security principle.
  • Audit Trail: Maintaining a documented timeline of discovery, patch deployment, and verification provides a defensible audit trail should a regulator or client request proof of risk mitigation.

Recommended Actions

  • Verify the installed Origin Viewer version across all workstations and upgrade to 10.4.0.25 or later.
  • Update your asset inventory and configuration‑management database to reflect the patched version.
  • Map the vulnerability to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) controls, and capture patch‑deployment logs as audit evidence.
  • Incorporate OGM‑file handling into your secure‑development lifecycle testing to prevent similar parsing flaws.

Source: Zero Day Initiative advisory – ZDI‑26‑586

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-586/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →