
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23716 is an out-of-bounds read vulnerability affecting Siemens Simcenter Femap and Simcenter Nastran, triggered when the applications parse specially crafted XDB files. All versions prior to V2512 of both products are affected. The vulnerability was published on February 10, 2026, with a patch advisory released by Siemens on February 11, 2026. It carries a CVSS v3.1 base score of 7.3 (High) and a CVSS v4.0 base score of 7.3 (High) (Siemens CERT, CISA ICS Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), arising from insufficient validation of input data when parsing XDB file structures in Simcenter Femap and Simcenter Nastran. An attacker can craft a malicious XDB file that, when opened by the application, causes the parser to read memory beyond the bounds of an allocated buffer, potentially enabling arbitrary code execution in the context of the current process. Exploitation requires local access and user interaction — specifically, a user must be convinced to open the malicious file. No public proof-of-concept code has been identified (Siemens CERT, CISA ICS Advisory).
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with the privileges of the user running the affected application, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker who achieves code execution could access sensitive engineering or simulation data, modify files, or disrupt application availability. The scope is limited to the local process context, with no direct impact on adjacent systems unless the compromised account has broader network access (Siemens CERT).
cmd.exe, powershell.exe, sh) or making unusual network connections.Siemens has released version V2512 for both Simcenter Femap and Simcenter Nastran, which addresses this vulnerability. Users should upgrade to V2512 or later as the primary remediation. As interim mitigations, organizations should restrict users from opening XDB files from untrusted or unknown sources, implement application whitelisting, and apply the principle of least privilege to accounts running these applications (Siemens CERT, CISA ICS Advisory).
CISA published an ICS advisory (ICSA-26-048-01) highlighting the vulnerability and recommending immediate patching. Security news outlets including IT Security News covered the advisory, and automated vulnerability tracking platforms such as RedPacket Security and VulnDB indexed the CVE shortly after disclosure. No notable independent researcher commentary or significant social media discussion has been identified beyond routine CVE tracking (CISA ICS Advisory, IT Security News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."