Junglewise Threat Intelligence

CVE-2026-50064: Siemens Solid Edge out-of-bounds write in PSM file parsing

CVE-2026-50064 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Siemens Solid Edge Se2025. Vendors: Siemens.

Executive brief

Solid Edge is a 3D design and product development software suite used by engineers across manufacturing and industrial sectors. An out-of-bounds write vulnerability in PSM file parsing allows attackers to execute arbitrary code when a user opens a specially crafted PSM file, potentially compromising design data, triggering denial of service, or serving as an entry point for broader system compromise.

Technical details

The vulnerability is an out-of-bounds write (CWE-787) that occurs during parsing of specially crafted PSM (part and sheet metal) files in Solid Edge SE2025 (versions before V225.0 Update 15) and SE2026 (versions before V226.0 Update 7). The attack requires local file access and user interaction to open a malicious PSM file; no network or authentication is required. Successful exploitation allows arbitrary code execution in the context of the Solid Edge process with the privileges of the user running the application. Siemens has released patches: SE2025 Update 15 and SE2026 Update 7.

Affected products

  • Siemens Solid Edge SE2025 All versions < V225.0 Update 15
  • Siemens Solid Edge SE2026 All versions < V226.0 Update 7

Timeline

  • 2026-08-11: disclosed: Siemens ProductCERT advisory SSA-621657 published
  • 2026-08-11: patched: Patches released: SE2025 Update 15, SE2026 Update 7

References

Related threats