CVE-2026-59086
Siemens has fixed vulnerabilities in various products such as Desigo, Parasolid, RUGGEDCOM, SIMATIC, Siveillance and Solid Edge. The vulnerabilities may enable a malicious actor to perform attacks that can lead to the following damage categories: - Denial-of-Service (DoS) - Data manipulation - Circumvention of a security measure - (Remote) code execution (root/admin rights) - (Remote) code execution (user rights) - Access to sensitive data - Privilege escalation The malicious actor requires access to the production environment for this. It is good practice not to have such an environment publicly accessible.
CSIRTS triage
- What
- Multiple vulnerabilities across Siemens products (Desigo, Parasolid, RUGGEDCOM, SIMATIC, Siveillance, Solid Edge) enable denial of service, code execution, privilege escalation, and data manipulation.
- Who is affected
- Deployments of affected Siemens products in production environments.
- Urgency
- High urgency; vulnerabilities enable remote code execution with root/admin rights and require production environment access.
- Action
- Apply Siemens patches for affected products addressing CVE-2026-3014, CVE-2026-23573, CVE-2026-50058 through CVE-2026-50063, and ensure production environments are not publicly accessible.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-59086
Get an email if CVE-2026-59086 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Advisory coverage (2)
- highCVE-2026-59086: A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastr…nvd · 2026-08-11
- unknownNCSC-2026-0282 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl · 2026-08-11
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-59086)