Arbitrary Code Execution in Siemens Simcenter Femap
Siemens Simcenter Femap is susceptible to arbitrary code execution via two out-of-bounds read vulnerabilities when parsing specially crafted BMP files.
CVE search metadata
CVE search record: CVE-2026-59700. Severity: high. CVSS: 7.8. EPSS: 0.11%. KEV: no. Product: Simcenter Femap. Brief: Arbitrary Code Execution in Siemens Simcenter Femap. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-simcenter-femap/
Siemens Simcenter Femap versions prior to V2606.0001 contain two vulnerabilities, CVE-2026-59700 and CVE-2026-59701, stemming from improper file parsing of BMP format images. These flaws are classified as out-of-bounds read vulnerabilities (CWE-125). An attacker can exploit these issues by providing a user with a specially crafted BMP file. If the victim opens the malicious file using the affected software, the application may crash or execute arbitrary code in the context of the user process. These vulnerabilities carry a CVSS score of 7.8 and are particularly relevant to the Critical Manufacturing sector where Simcenter Femap is deployed for engineering simulation tasks.
Impact
Successful exploitation allows for remote code execution within the security context of the user running the software, potentially leading to unauthorized data access, system disruption, or further compromise of engineering workstations. The impact is categorized as high given the potential for full compromise of the local application process.
Recommendation
- Immediately update Siemens Simcenter Femap to version V2606.0001 or later to remediate CVE-2026-59700 and CVE-2026-59701.
- Implement file access controls and restrict the opening of untrusted files within engineering environments to mitigate the risk of user-driven exploitation.
- Audit endpoint software to identify legacy installations of Siemens Simcenter Femap that require patching.
Immediate actions
Patch all instances of Siemens Simcenter Femap to V2606.0001
Mitigations
Restrict the ability of engineering workstations to open untrusted external files
CVE-2026-59700, CVE-2026-59701