Siemens Simcenter Femap
View CSAF Summary Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version. The following versions of Siemens Simcenter Femap are affected: Simcenter Femap vers:intdot/<2606.0001 (CVE-2026-59700, CVE-2026-59701) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Simcenter Femap Out-of-bounds Read Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-59700 The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Femap Vendor: Siemens Product Version: Simcenter Femap < V2606.0001 Product Status: known_affected Remediations Vendor fix Update to V2606.0001 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2026-59701 The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Femap Vendor: Siemens Product Version: Simcenter Femap < V2606.0001 Product Status: known_affected Remediations Vendor fix Update to V2606.0001 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version
CSIRTS triage
- What
- Out-of-bounds read vulnerability in BMP file parsing allows application crash or arbitrary code execution when reading malicious files.
- Who is affected
- Simcenter Femap users tricked into opening untrusted BMP files, affecting critical manufacturing deployments.
- Urgency
- Immediate; critical severity with CVSS 7.8 and potential code execution via file parsing.
- Action
- Update Simcenter Femap to version 2606.0001 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Simcenter Femap
Get an email when a new Simcenter Femap advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-11
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-597000.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-597010.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59700 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59701 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-59701: A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affect…nvd
- highCVE-2026-59700: A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affect…nvd
- unknownNCSC-2026-0282 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl
More from CISA Cybersecurity Advisories
- criticalJohnson Controls Metasys2026-08-13
- criticalSiemens Siveillance Video2026-08-13
- criticalFlow Neuroscience FL-1002026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13
- criticalJohnson Controls Inc. Airwall2026-08-13