{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/simcenter-nastran/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-59700"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Simcenter Femap","Simcenter Nastran"],"_cs_severities":["high"],"_cs_tags":["vulnerability","industrial-control-systems","ics","cve-2026-59086","stack-overflow","rce"],"_cs_type":"advisory","_cs_vendors":["Siemens"],"content_html":"\u003cp\u003eSiemens Simcenter Femap versions prior to V2606.0001 contain two vulnerabilities, CVE-2026-59700 and CVE-2026-59701, stemming from improper file parsing of BMP format images. These flaws are classified as out-of-bounds read vulnerabilities (CWE-125). An attacker can exploit these issues by providing a user with a specially crafted BMP file. If the victim opens the malicious file using the affected software, the application may crash or execute arbitrary code in the context of the user process. These vulnerabilities carry a CVSS score of 7.8 and are particularly relevant to the Critical Manufacturing sector where Simcenter Femap is deployed for engineering simulation tasks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for remote code execution within the security context of the user running the software, potentially leading to unauthorized data access, system disruption, or further compromise of engineering workstations. The impact is categorized as high given the potential for full compromise of the local application process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update Siemens Simcenter Femap to version V2606.0001 or later to remediate CVE-2026-59700 and CVE-2026-59701.\u003c/li\u003e\n\u003cli\u003eImplement file access controls and restrict the opening of untrusted files within engineering environments to mitigate the risk of user-driven exploitation.\u003c/li\u003e\n\u003cli\u003eAudit endpoint software to identify legacy installations of Siemens Simcenter Femap that require patching.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T17:49:22Z","date_published":"2026-08-13T16:53:08Z","id":"https://feed.craftedsignal.io/briefs/2026-08-siemens-simcenter-femap/","summary":"Siemens Simcenter Femap is susceptible to arbitrary code execution via two out-of-bounds read vulnerabilities when parsing specially crafted BMP files.","title":"Arbitrary Code Execution in Siemens Simcenter Femap","url":"https://feed.craftedsignal.io/briefs/2026-08-siemens-simcenter-femap/"}],"language":"en","title":"CraftedSignal Threat Feed - Simcenter Nastran","version":"https://jsonfeed.org/version/1.1"}