Skip to content
SiemensCVE-2026-59700

Siemens Simcenter Femap: out-of-bounds read

High7.3CVE-2026-59700 · Published Aug 11, 2026 · updated Aug 28, 2026

A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.

Siemens advisory

Affected versions

PackageAffectedFixed in
Simcenter Femap
Product
< V2606.0001V2606.0001
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-125

More Siemens advisories

All Siemens
Advisory
Siemens License Server (SLS): path traversal
High8.7Aug 11
Siemens Parasolid: out-of-bounds read
High7.3Aug 11
Siemens License Server (SLS): privilege escalation
High8.3Aug 11
Siemens SIMATIC IoT2050 Advanced: remote code execution
Critical10.0Aug 11
Siemens Simcenter: code execution
High7.3Aug 11
Siemens Desigo: denial of service
Medium5.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.