<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-Report - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-report/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 16:53:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-report/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Memory Corruption Vulnerabilities in Siemens Solid Edge</title><link>https://feed.craftedsignal.io/briefs/2026-08-siemens-solid-edge-vulns/</link><pubDate>Thu, 13 Aug 2026 16:53:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-siemens-solid-edge-vulns/</guid><description>Siemens Solid Edge is affected by multiple memory corruption vulnerabilities, including out-of-bounds read/write and use-after-free, allowing arbitrary code execution via specially crafted PAR, PSM, or DFT files.</description><content:encoded><![CDATA[<p>Siemens has disclosed seven vulnerabilities affecting Solid Edge SE2025 and SE2026, stemming from improper memory handling during the parsing of proprietary file formats (PAR, PSM, and DFT). The vulnerabilities - identified as CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, and CVE-2026-50064 - include out-of-bounds read/write errors and use-after-free conditions. These flaws reside within the application's file parsing logic and can be leveraged by an attacker to trigger application crashes or execute arbitrary code in the context of the user running the software. As these files are frequently shared in engineering and manufacturing environments, this represents a significant risk for organizations within the Critical Manufacturing sector. Users must update to Solid Edge SE2025 V225.0.15 or SE2026 V226.0.7 or later to mitigate these issues.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could result in full system compromise for the affected user's workstation through arbitrary code execution. These vulnerabilities primarily affect the Critical Manufacturing sector globally. The impact ranges from localized application crashes causing denial of service in design workflows to complete code execution, which could facilitate lateral movement or the theft of sensitive engineering data stored within the CAD environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update all instances of Siemens Solid Edge SE2025 to V225.0.15 or later immediately.</li>
<li>Update all instances of Siemens Solid Edge SE2026 to V226.0.7 or later immediately.</li>
<li>Implement file integrity monitoring and restrict the execution of Solid Edge files from untrusted or external sources within the enterprise environment.</li>
<li>Monitor for abnormal process behavior or unexpected crashes of the Solid Edge application binaries, which may indicate attempted exploitation of these memory corruption flaws.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>critical-manufacturing</category><category>memory-corruption</category><category>cve-report</category></item></channel></rss>