
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59701 is an out-of-bounds read vulnerability in Siemens Simcenter Femap, a finite element analysis (FEA) pre/post-processing application, triggered when parsing specially crafted BMP files. All versions prior to V2606.0001 are affected. The vulnerability was published on August 11, 2026, with a patch available in V2606.0001. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.3 (High) (GitHub Advisory, Siemens CERT).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), occurring in Simcenter Femap's BMP file parser, which fails to properly validate buffer boundaries when processing image data from specially crafted BMP files. An attacker can exploit this flaw by supplying a malicious BMP file that causes the application to read memory beyond the intended buffer, potentially enabling code execution in the context of the current process. Exploitation requires local access and user interaction — specifically, a victim must open the malicious file within the application. No public proof-of-concept or technical write-up has been identified at this time (GitHub Advisory, Siemens CERT).
Successful exploitation could allow an attacker to execute arbitrary code in the context of the Simcenter Femap process, resulting in high impact to confidentiality, integrity, and availability of the affected system. Since Simcenter Femap is used in engineering and manufacturing environments, compromise could expose sensitive design data or simulation models. The scope is limited to the vulnerable system (no subsequent system impact), but code execution under the user's process context could enable further local privilege escalation or lateral movement depending on the environment (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of publication. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though a CISA ICS advisory (ICSA-26-225-11) was published referencing this CVE. The EPSS score is approximately 0.113% (2nd percentile), indicating a low near-term probability of exploitation. Exploitation is not automatable, as it requires user interaction to open a malicious BMP file (GitHub Advisory, CISA ICS Advisory).
femap.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, wscript.exe) or making unusual network connections.Siemens has released a patch in Simcenter Femap version V2606.0001, which resolves this vulnerability; users should upgrade immediately (Siemens CERT). As interim workarounds, organizations should restrict handling of BMP files from untrusted or external sources, implement application whitelisting, and apply the principle of least privilege to limit the impact of any potential code execution. Users should be advised not to open BMP files from unknown or unverified sources within Simcenter Femap until the patch is applied.
Siemens published a product security advisory (SSA-584312) addressing this vulnerability, and CISA issued an ICS advisory (ICSA-26-225-11) to notify industrial control system operators (CISA ICS Advisory, Siemens CERT). No notable independent researcher commentary or significant social media discussion has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."