Skip to content
SiemensCVE-2026-59086

Siemens Simcenter: code execution

High7.3CVE-2026-59086 · Published Aug 11, 2026 · updated Aug 28, 2026

A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.

Siemens advisory

Affected versions

PackageAffectedFixed in
Simcenter Femap
Product
< V2606V2606
Simcenter Nastran
Product
< V2606V2606
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-121

More Siemens advisories

All Siemens
Advisory
Siemens License Server (SLS): path traversal
High8.7Aug 11
Siemens Parasolid: out-of-bounds read
High7.3Aug 11
Siemens License Server (SLS): privilege escalation
High8.3Aug 11
Siemens SIMATIC IoT2050 Advanced: remote code execution
Critical10.0Aug 11
Siemens Desigo: denial of service
Medium5.3Aug 11
Siemens Simcenter Femap: out-of-bounds read
High7.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.