IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-621657: File Parsing Vulnerabilities in Solid Edge Before Version SE2026 Update 7

HIGH
CVSS 7.8
Date 2026-08-11T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (7)

CVE ID CVSS Score Severity Description
CVE-2026-50062 7.8 high
CVE-2026-50062. The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
CVE-2026-50060 7.8 high
CVE-2026-50060. The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
CVE-2026-50059 7.8 high
CVE-2026-50059. The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
CVE-2026-50058 7.8 high
CVE-2026-50058. The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
CVE-2026-50063 7.8 high
CVE-2026-50063. The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
CVE-2026-50061 7.8 high
CVE-2026-50061. The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
CVE-2026-50064 7.8 high
CVE-2026-50064. The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.

// Remediations (2)

Patch: Update to V225.0 Update 15 or later version
Update to V225.0 Update 15 or later version
Patch: Update to V226.0 Update 7 or later version
Update to V226.0 Update 7 or later version

// References