Executive brief
Solid Edge is a professional 3D CAD design and product development software suite used by engineering teams. A use-after-free memory vulnerability in the DFT file parser allows attackers to execute arbitrary code when users open specially crafted design files, potentially compromising design data and system integrity.
Technical details
The vulnerability (CVE-2026-50060) is a use-after-free flaw in Solid Edge's DFT file parser triggered when parsing specially crafted files. The attack requires user interaction (opening a malicious file) but requires no privileges or authentication. An attacker can achieve arbitrary code execution in the context of the Solid Edge process. Siemens has released patches: Solid Edge SE2025 Update 15 and SE2026 Update 7 address this and related file parsing vulnerabilities (CVE-2026-50058 through CVE-2026-50064 affecting DFT, PAR, and PSM file formats).
Affected products
- Siemens Solid Edge SE2025 All versions < V225.0 Update 15
- Siemens Solid Edge SE2026 All versions < V226.0 Update 7
Timeline
- 2026-08-11: disclosed: Public disclosure via Siemens ProductCERT advisory SSA-621657
- 2026-08-11: patched: Patches released: SE2025 Update 15 and SE2026 Update 7