Siemens Simcenter Nastran
August 18, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL
View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Simcenter Nastran are affected: Simcenter Femap vers:intdot/<2606 (CVE-2026-59086) Simcenter Nastran vers:intdot/<2606 (CVE-2026-59086) CVSS Vendor Equipment Vulnerabilities v3 7. 8 Siemens Siemens Simcenter Nastran Stack-based Buffer Overflow Background Critical Infrastructure Sectors: Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-59086 The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Nastran Vendor: Siemens Product Version: Simcenter Femap < V2606, Simcenter Nastran < V2606 Product Status:known_affected Remediations Vendor fixUpdate to V2606 or later versionhttps://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-121 Stack-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3. 1 7. 8 HIGH CVSS:3. 1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Acknowledgments Michael Heinzl reported this vulnerability to Siemens ProductCERT. General Recommendations As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate... ๐ **Analyst Note:** CVE-2026-59086 in Simcenter Nastran is a classic stack-based buffer overflow (CWE-121) requiring user interaction to trigger. The CVSS 7. 8 rating reflects local access requirements but the high impact on confidentiality, integrity, and availability. Organizations using these engineering tools should prioritize updating to V2606 given the public PoC availability.
Key Takeaways
- Siemens Simcenter Nastran and Femap versions below V2606 contain a stack overflow vulnerability parsed as CVE-2026-59086.
- CVE-2026-59086 is triggered when an application binary reads a maliciously crafted string as a file argument from a user.
- Successful exploitation allows an attacker to achieve remote code execution in the context of the current process.
- Siemens recommends updating to V2606 or later; a vendor advisory is available at Siemens ProductCERT.