Skip to content
SiemensCVE-2026-50061

Siemens Solid Edge: use after free

High7.3CVE-2026-50061 · Published Aug 11, 2026 · updated Sep 10, 2026

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.

Siemens advisory

Affected versions

PackageAffectedFixed in
Solid Edge SE2025
Product
< V225.0 Update 15V225.0 Update 15
Solid Edge SE2026
Product
< V226.0 Update 7V226.0 Update 7
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-416

More Siemens advisories

All Siemens
Advisory
Siemens License Server (SLS): path traversal
High8.7Aug 11
Siemens Parasolid: out-of-bounds read
High7.3Aug 11
Siemens License Server (SLS): privilege escalation
High8.3Aug 11
Siemens SIMATIC IoT2050 Advanced: remote code execution
Critical10.0Aug 11
Siemens Simcenter: code execution
High7.3Aug 11
Siemens Desigo: denial of service
Medium5.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.