Vulnerabilities · 42 days ago

Solid Edge File Parsing Puts CAD Workstations at Risk

Siemens and CISA published a Solid Edge advisory for seven file-parsing flaws in SE2025 and SE2026, with fixes in SE2025 Update 15 and SE2026 Update 7. The affected formats are PAR, PSM, and DFT, and the bugs can crash the app or let an attacker run code in the Solid Edge process.

The issue is in the parser: opening a specially crafted CAD file is enough to trigger the flaw, so the dangerous input is hidden in what looks like a normal project file. That makes the engineering workstation the execution point, not just the installed application.

For teams that trade design files with suppliers or other engineering groups, the exposure sits in the workflow that opens outside files. Until the patched build is in place, any workstation that trusts those files inherits the same risk.

CVEs in this update

7 CVEs

0 critical · 7 high · 0 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-50058 · 7.8 HIGH

Highest EPSS: CVE-2026-50058 · 0.16%

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-08-14

Editions

Related stories