Executive brief
Solid Edge is a widely-used 3D design and product development suite. A use-after-free vulnerability in its file parser could allow an attacker to execute arbitrary code when a user opens a malicious DFT file, potentially compromising design data and engineering systems.
Technical details
CVE-2026-50061 is a use-after-free vulnerability (CWE-416) in Solid Edge's DFT file parser. The flaw is triggered when the application processes specially crafted DFT (Solid Edge drawing) files, leading to memory corruption. The attack requires user interaction (opening a file) but no authentication; the attacker can achieve arbitrary code execution in the application's context. Patches are available: Solid Edge SE2025 should update to V225.0 Update 15 or later, and SE2026 should update to V226.0 Update 7 or later.
Affected products
- Siemens Solid Edge SE2025 All versions < V225.0 Update 15
- Siemens Solid Edge SE2026 All versions < V226.0 Update 7
Timeline
- 2026-08-11: disclosed