CVE-2026-23716
published 2026-02-10CVE-2026-23716: A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an…
PriorityP339high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.13%
3.2th percentile
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simcenter_femap | < V2512 | V2512 |
| siemens | simcenter_femap | < 2512.0000 | 2512.0000 |
| siemens | simcenter_nastran | < V2512 | V2512 |
| siemens | simcenter_nastran | < 2512.0000 | 2512.0000 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv4.07.3HIGHCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Simcenter Femap and Nastran
cisa_ics·2026-02-17·CVSS 7.8
[HIGH] Siemens Simcenter Femap and Nastran
ICS Advisory
##
Siemens Simcenter Femap and Nastran
Release DateFebruary 17, 2026
Alert CodeICSA-26-048-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Siemens Simcenter Femap and Nastran is affected by multiple file parsing vulnerabilities that could be triggered when the application reads files in NDB and XDB formats. If a user is tricked to open a malicious file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Simcenter Femap and Nastran are affected:
- Simcenter Femap vers:intd
GHSA
GHSA-vw6h-3mwh-pr33: A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)
ghsa_unreviewed·2026-02-10
CVE-2026-23716 [HIGH] CWE-125 GHSA-vw6h-3mwh-pr33: A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23717 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2026-23717 [HIGH] CVE-2026-23717 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23717 :
Siemens Simcenter Femap vulnerability analysis and mitigation
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process.
Source : NVD
## 7.3
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Siemens Simcenter Femap
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:siemens:simcenter_femap
Sources
Wiz
CVE-2025-40829 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2025-40829 [HIGH] CVE-2025-40829 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-40829 :
Siemens Simcenter Femap vulnerability analysis and mitigation
A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27146)
Source : NVD
## 7.3
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.3
Affected Technologies
Siemens Simcenter Femap
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:siemens:simcenter_femap
Sources
Windows Severity HI
Wiz
CVE-2026-23719 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2026-23719 [HIGH] CVE-2026-23719 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23719 :
Siemens Simcenter Femap vulnerability analysis and mitigation
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process.
Source : NVD
## 7.3
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Siemens Simcenter Femap
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:siemens:simcenter_femap
Sources
Wiz
CVE-2026-23718 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2026-23718 [HIGH] CVE-2026-23718 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23718 :
Siemens Simcenter Femap vulnerability analysis and mitigation
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process.
Source : NVD
## 7.3
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Siemens Simcenter Femap
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:siemens:simcenter_femap
Sources
Wiz
CVE-2026-23715 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2026-23715 [HIGH] CVE-2026-23715 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23715 :
Siemens Simcenter Femap vulnerability analysis and mitigation
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds write vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process.
Source : NVD
## 7.3
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Siemens Simcenter Femap
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:siemens:simcenter_femap
Source
Wiz
CVE-2026-23716 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2026-23716 [HIGH] CVE-2026-23716 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23716 :
Siemens Simcenter Femap vulnerability analysis and mitigation
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process.
Source : NVD
## 7.3
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Siemens Simcenter Femap
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:siemens:simcenter_femap
Sources
Wiz
CVE-2026-23720 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2026-23720 [HIGH] CVE-2026-23720 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23720 :
Siemens Simcenter Femap vulnerability analysis and mitigation
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process.
Source : NVD
## 7.3
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Siemens Simcenter Femap
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:siemens:simcenter_femap
Sources
Wiz
CVE-2025-40800 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2025-40800 [CRITICAL] CVE-2025-40800 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-40800 :
Siemens Simcenter Femap vulnerability analysis and mitigation
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0 Update 10), Solid Edge SE2026 (All versions < V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
Source : NVD
## 9.1
Score
Published December 9, 2025
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Siemens
2026-02-10
Published