Junglewise Threat Intelligence

CVE-2026-59086: Siemens Simcenter stack overflow in argument parsing

CVE-2026-59086 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Siemens Simcenter Femap. Vendors: Siemens.

Executive brief

Simcenter Femap and Simcenter Nastran are widely-used simulation and finite element analysis tools used by engineers to design and analyze complex products. A stack overflow vulnerability in these applications allows attackers to execute arbitrary code if a user runs the application with a specially crafted string argument. An attacker could exploit this to gain full control over engineering workstations and compromise sensitive design data.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in both Simcenter Femap and Simcenter Nastran where an application binary improperly parses specially crafted strings passed as file arguments, leading to stack memory corruption. The vulnerability requires local access and user interaction—an attacker must trick a user into running the application with a malicious string argument. Successful exploitation allows remote code execution with the privileges of the current process, potentially compromising design data and system integrity. Patches are available: both products should be updated to V2606 or later.

Affected products

  • Siemens Simcenter Femap < V2606
  • Siemens Simcenter Nastran < V2606

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Updates to V2606 available for both products

References

Related threats