Siemens Solid Edge
View CSAF Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Solid Edge are affected: Solid Edge SE2025 vers:intdot/<225.0.15 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064) Solid Edge SE2026 vers:intdot/<226.0.7 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Solid Edge Out-of-bounds Read, Out-of-bounds Write, Use After Free Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-50058 The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Solid Edge Vendor: Siemens Product Version: Solid Edge SE2025 < V225.0.15, Solid Edge SE2026 < V226.0.7 Product Status: known_affected Remediations Vendor fix Update to V225.0 Update 15 or later version https://support.sw.siemens.com/product/246738425/ Vendor fix Update to V226.0 Update 7 or later version https://support.sw.siemens.com/product/246738425/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2026-50059 The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context o
CSIRTS triage
- What
- Multiple file parsing vulnerabilities in PAR, PSM, and DFT format handling allow crash or arbitrary code execution when reading specially crafted files.
- Who is affected
- Siemens Solid Edge SE2025 and SE2026 users opening untrusted design files.
- Urgency
- Immediate; critical severity with CVSS 7.8 and direct code execution capability via file parsing.
- Action
- Update Solid Edge SE2025 to 225.0.15 or later and SE2026 to 226.0.7 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Solid Edge
Get an email when a new Solid Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-12
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-500580.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500590.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500600.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500610.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500620.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500630.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-500640.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-50058 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50059 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50060 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50061 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50062 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50063 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50064 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-50064: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), So…nvd
- highCVE-2026-50063: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), So…nvd
- highCVE-2026-50062: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), So…nvd
- highCVE-2026-50061: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), So…nvd
- highCVE-2026-50060: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), So…nvd
- highCVE-2026-50059: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), So…nvd
- highCVE-2026-50058: A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), So…nvd
- unknownNCSC-2026-0282 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl
More from CISA Cybersecurity Advisories
- criticalJohnson Controls Metasys2026-08-13
- criticalSiemens Siveillance Video2026-08-13
- criticalFlow Neuroscience FL-1002026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13
- criticalJohnson Controls Inc. Airwall2026-08-13