
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22923 is a stack-based buffer overflow vulnerability (CWE-121) in Siemens NX, a widely used CAD/CAM/CAE software platform. The flaw exists in the PDF export process and affects all versions of NX and NX (Managed Mode) prior to V2512. It was published on February 10, 2026, with a patch advisory released by Siemens. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.3 (High) (Siemens CERT, Red Hat CVE).
The vulnerability is classified as a stack-based buffer overflow (CWE-121), rooted in insufficient data validation during the PDF export process within Siemens NX. An attacker with local access can interfere with internal data structures during a PDF export operation, potentially overwriting stack memory and redirecting execution flow to arbitrary code. Exploitation requires user interaction — specifically, a user must trigger a PDF export — and no elevated privileges are needed. No public proof-of-concept or detailed technical write-up has been identified at this time (Siemens CERT, CISA ICS Advisory).
Successful exploitation of this vulnerability can result in arbitrary code execution on the affected system, with high impact to confidentiality, integrity, and availability. An attacker could gain control of the application process, access sensitive design or engineering data, modify files, or cause a denial of service. Because NX is commonly used in industrial and engineering environments, compromise could extend to sensitive intellectual property or operational systems (Siemens CERT, Red Hat CVE).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for CVE-2026-22923 at this time. The EPSS score is approximately 0.015%, indicating a very low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for local access and user interaction, limiting the attack surface (Siemens CERT, CISA ICS Advisory).
Siemens has released a patch addressing this vulnerability; users should upgrade NX and NX (Managed Mode) to version V2512 or later. As interim mitigations, organizations should restrict local access to systems running NX to authorized personnel only and apply the principle of least privilege. Monitoring for unusual PDF export activity or unexpected process behavior on NX workstations is also recommended. Full patch details are available in the Siemens ProductCERT advisory (Siemens CERT, CISA ICS Advisory).
The vulnerability received standard coverage from ICS security aggregators and vulnerability databases shortly after disclosure. CISA published an ICS advisory (ICSA-26-043-08) referencing the flaw, and Siemens issued its ProductCERT advisory (SSA-535115). Social media activity was limited to automated vulnerability notification accounts on Mastodon and similar platforms, with no notable researcher commentary or broader community discussion identified (CISA ICS Advisory, Siemens CERT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."