Solid Edge File Parsing Puts CAD Workstations at Risk
Siemens and CISA published a Solid Edge advisory for seven file-parsing flaws in SE2025 and SE2026, with fixes in SE2025 Update 15 and SE2026 Update 7. The affected formats are PAR, PSM, and DFT, and the bugs can crash the app or let an attacker run code in the Solid Edge process.
The issue is in the parser: opening a specially crafted CAD file is enough to trigger the flaw, so the dangerous input is hidden in what looks like a normal project file. That makes the engineering workstation the execution point, not just the installed application.
For teams that trade design files with suppliers or other engineering groups, the exposure sits in the workflow that opens outside files. Until the patched build is in place, any workstation that trusts those files inherits the same risk.
Siemens Simcenter Nastran Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument.
Siemens Solid Edge Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format.