As cited
Copy frozen at (site build).
vulnerabilities
Siemens Simcenter Nastran
Siemens Simcenter Nastran and Simcenter Femap versions prior to V2606 contain a stack-based buffer overflow vulnerability (CVE-2026-59086, CVSS 7.8) that can be triggered when an application binary processes a malicious string argument. An attacker could exploit this flaw to execute arbitrary code in the context of the current process if a user is tricked into running the application with a crafted input. Siemens has released patched versions and recommends immediate updates.
Why it matters: Organizations using Simcenter Nastran or Femap in manufacturing, defense, energy, healthcare, or transportation must update to V2606 or later to prevent code execution attacks that could compromise critical design and simulation workflows.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Siemens Simcenter Nastran
Siemens Simcenter Nastran and Simcenter Femap versions before V2606 contain a stack overflow vulnerability (CVE-2026-59086) that can be triggered when application binaries parse specially crafted strings as file arguments. An attacker could exploit this to achieve remote code execution in the context of the running process if a user executes an affected binary with malicious input. Siemens has released patched versions and recommends users update immediately.
Why it matters: Engineers and organizations using Simcenter Nastran or Femap in critical manufacturing, defense, energy, healthcare, and transportation sectors must patch to V2606 or later to prevent arbitrary code execution from a local attack vector requiring user interaction.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Siemens Simcenter Nastran
Siemens Simcenter Nastran and Simcenter Femap versions before V2606 contain a stack overflow vulnerability (CVE-2026-59086) that can be triggered when application binaries parse specially crafted strings as file arguments. An attacker could exploit this to achieve remote code execution in the context of the running process if a user executes an affected binary with malicious input. Siemens has released patched versions and recommends users update immediately.
Why it matters: Engineers and organizations using Simcenter Nastran or Femap in critical manufacturing, defense, energy, healthcare, and transportation sectors must patch to V2606 or later to prevent arbitrary code execution from a local attack vector requiring user interaction.
- Source published
- First seen by Cybersecurity Tracker