CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64629

criticalCVSS 7.8covered by 3 sourcesfirst seen 2026-08-11
View CSAF Summary Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629) Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64629) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Parasolid Out-of-bounds Read Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-64629 The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Parasolid Vendor: Siemens Product Version: Parasolid V38.0 < V38.0.235, Parasolid V38.1 < V38.1.230 Product Status: known_affected Remediations Vendor fix Update to V38.0.235 or later version https://support.sw.siemens.com/product/258316782/ Vendor fix Update to V38.1.230 or later version https://support.sw.siemens.com/product/258316782/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial

CSIRTS triage

What
Out-of-bounds read vulnerability in X_T file parsing allows application crash or arbitrary code execution when reading specially crafted files.
Who is affected
Siemens Parasolid V38.0 and V38.1 users in critical manufacturing opening untrusted CAD files.
Urgency
Immediate; critical severity with CVSS 7.8 and potential code execution via file parsing.
Action
Update Parasolid V38.0 to 38.0.235 or later and V38.1 to 38.1.230 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64629

Get an email if CVE-2026-64629 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-64629

CVE.org record

Embed the live status

CVE-2026-64629 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64629 status](https://www.csirts.com/badge/CVE-2026-64629)](https://www.csirts.com/cve/CVE-2026-64629)