CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Siemens Parasolid

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4387

As cited

Copy frozen at (site build).

vulnerabilities

Siemens Parasolid

Siemens Parasolid contains an out-of-bounds read vulnerability (CVE-2026-64629) triggered when parsing specially crafted X_T format files, with a CVSS score of 7.8. The flaw could allow attackers to crash the application or execute arbitrary code. Siemens has released patched versions V38.0.235 and V38.1.230 and recommends immediate updates.

Why it matters: Organizations deploying Parasolid in critical manufacturing environments worldwide must update to patched versions immediately, as local attackers can trigger code execution by supplying malicious X_T files.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Siemens Parasolid

Siemens has patched an out-of-bounds read vulnerability (CVE-2026-64629) in Parasolid versions 38.0 and 38.1 that could allow code execution when parsing specially crafted X_T files. Affected users should update to Parasolid V38.0.235 or V38.1.230 or later.

Why it matters: Critical manufacturing organizations worldwide using Parasolid for computer-aided design must patch immediately, as attackers can trigger code execution by sending malicious files to local users.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Siemens Parasolid

Siemens has patched an out-of-bounds read vulnerability (CVE-2026-64629) in Parasolid versions 38.0 and 38.1 that could allow code execution when parsing specially crafted X_T files. Affected users should update to Parasolid V38.0.235 or V38.1.230 or later.

Why it matters: Critical manufacturing organizations worldwide using Parasolid for computer-aided design must patch immediately, as attackers can trigger code execution by sending malicious files to local users.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary