Junglewise Threat Intelligence

CVE-2026-50059: Siemens Solid Edge out-of-bounds write in DFT file parsing

CVE-2026-50059 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Siemens Solid Edge Se2025. Vendors: Siemens.

Executive brief

Solid Edge is a professional 3D design and product development software used by manufacturing and engineering teams. A memory safety flaw in its file parser allows attackers to craft malicious DFT (Solid Edge drawing) files that, when opened by a user, can crash the application or execute arbitrary code with the user's privileges, potentially compromising sensitive design data and engineering systems.

Technical details

CVE-2026-50059 is an out-of-bounds write vulnerability (CWE-787) in Solid Edge's DFT file parser. The vulnerability is triggered when the application processes specially crafted DFT files, allowing an attacker to write data beyond allocated buffer boundaries. The attack vector is local with user interaction required (user must open a malicious file). Successful exploitation enables arbitrary code execution in the context of the running Solid Edge process. Siemens has released patches: SE2025 requires Update 15 or later, and SE2026 requires Update 7 or later.

Affected products

  • Siemens Solid Edge SE2025 All versions < V225.0 Update 15
  • Siemens Solid Edge SE2026 All versions < V226.0 Update 7

Timeline

  • 2026-08-11: disclosed: Siemens Security Advisory SSA-621657 published
  • 2026-08-11: patched: Patches available: SE2025 Update 15, SE2026 Update 7

References

Related threats