Siemens Simcenter Nastran
View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Simcenter Nastran are affected: Simcenter Femap vers:intdot/<2606 (CVE-2026-59086) Simcenter Nastran vers:intdot/<2606 (CVE-2026-59086) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Simcenter Nastran Stack-based Buffer Overflow Background Critical Infrastructure Sectors: Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-59086 The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Nastran Vendor: Siemens Product Version: Simcenter Femap < V2606, Simcenter Nastran < V2606 Product Status: known_affected Remediations Vendor fix Update to V2606 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-121 Stack-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Acknowledgments Michael Heinzl reported this vulnerability to Siemens ProductCERT. General Recommendations As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protec
CSIRTS triage
- What
- A stack overflow vulnerability in Simcenter Nastran triggered when reading arbitrary strings as file arguments, allowing remote code execution.
- Who is affected
- Users of Siemens Simcenter Nastran and Simcenter Femap versions prior to 2606 who run the application with untrusted input.
- Urgency
- Critical; stack overflow vulnerabilities in engineering software can be reliably exploited for code execution.
- Action
- Update Simcenter Nastran and Simcenter Femap to version 2606 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Simcenter Nastran
Get an email when a new Simcenter Nastran advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-590860.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59086 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from CISA Cybersecurity Advisories
- highCISA Adds One Known Exploited Vulnerability to Catalog2026-08-19
- criticalDefending Against an Active Threat to Siemens S7 Series PLCs2026-08-19
- highCISA Adds Four Known Exploited Vulnerabilities to Catalog2026-08-18
- criticalCISA Malcolm2026-08-18
- highCISA Adds One Known Exploited Vulnerability to Catalog2026-08-17