Vulnerabilities · 42 days ago
Siemens and CISA published a Solid Edge advisory for seven file-parsing flaws in SE2025 and SE2026, with fixes in SE2025 Update 15 and SE2026 Update 7. The affected formats are PAR, PSM, and DFT, and the bugs can crash the app or let an attacker run code in the Solid Edge process.
The issue is in the parser: opening a specially crafted CAD file is enough to trigger the flaw, so the dangerous input is hidden in what looks like a normal project file. That makes the engineering workstation the execution point, not just the installed application.
For teams that trade design files with suppliers or other engineering groups, the exposure sits in the workflow that opens outside files. Until the patched build is in place, any workstation that trusts those files inherits the same risk.
CVEs in this update
7 CVEs
0 critical · 7 high · 0 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-50058 · 7.8 HIGH
Highest EPSS: CVE-2026-50058 · 0.16%
3 sources covering this story
Siemens Simcenter Nastran | CISA
Siemens Simcenter Nastran Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument.
Siemens Solid Edge Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format.
Siemens LOGO! Soft Comfort | CISA
Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms.
Siemens RUGGEDCOM APE1808 | CISA
Siemens RUGGEDCOM APE1808 Summary Fortinet has published information on vulnerabilities in FortiOS.
Aggiornamenti per prodotti Siemens
Siemens ha rilasciato aggiornamenti di sicurezza per sanare molteplici vulnerabilità nei propri prodotti, di cui 1 con gravità “critica” e 13 con gravità “alta”.
Kwetsbaarheden verholpen in Siemens producten
Siemens heeft kwetsbaarheden verholpen in diverse producten als Desigo, Parasolid, RUGGEDCOM, SIMATIC, Siveillance en Solid Edge.
Part of the PlainSec briefing for 2026-08-14