IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-069220: Stack Overflow Vulnerability in Simcenter Nastran Before V2606

HIGH
CVSS 7.8
Date 2026-08-11T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released a new version for Simcenter Nastran and recommends to update to the latest version.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-59086 7.8 high
CVE-2026-59086. The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.

// Remediations (1)

Patch: Update to V2606 or later version
Update to V2606 or later version

// References