CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59700

criticalCVSS 7.8covered by 3 sourcesfirst seen 2026-08-11
View CSAF Summary Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version. The following versions of Siemens Simcenter Femap are affected: Simcenter Femap vers:intdot/<2606.0001 (CVE-2026-59700, CVE-2026-59701) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Simcenter Femap Out-of-bounds Read Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-59700 The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Femap Vendor: Siemens Product Version: Simcenter Femap < V2606.0001 Product Status: known_affected Remediations Vendor fix Update to V2606.0001 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2026-59701 The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Femap Vendor: Siemens Product Version: Simcenter Femap < V2606.0001 Product Status: known_affected Remediations Vendor fix Update to V2606.0001 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version

CSIRTS triage

What
Out-of-bounds read vulnerability in BMP file parsing allows application crash or arbitrary code execution when reading malicious files.
Who is affected
Simcenter Femap users tricked into opening untrusted BMP files, affecting critical manufacturing deployments.
Urgency
Immediate; critical severity with CVSS 7.8 and potential code execution via file parsing.
Action
Update Simcenter Femap to version 2606.0001 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-59700

Get an email if CVE-2026-59700 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-59700

CVE.org record

Embed the live status

CVE-2026-59700 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59700 status](https://www.csirts.com/badge/CVE-2026-59700)](https://www.csirts.com/cve/CVE-2026-59700)