Threat Advisory

Siemens Solid Edge Flaws Allow Code Execution Through Specially Crafted Files

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

### Vulnerability Summary

Multiple high-severity file parsing vulnerabilities have been identified in Siemens Solid Edge SE2025 and SE2026. The flaws affect the processing of specially crafted DFT, PAR, and PSM files and include out-of-bounds read, out-of-bounds write, and use-after-free vulnerabilities. Successful exploitation could allow an attacker to crash the application or execute arbitrary code in the context of the current process.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

### Vulnerability Summary

Multiple high-severity file parsing vulnerabilities have been identified in Siemens Solid Edge SE2025 and SE2026. The flaws affect the processing of specially crafted DFT, PAR, and PSM files and include out-of-bounds read, out-of-bounds write, and use-after-free vulnerabilities. Successful exploitation could allow an attacker to crash the application or execute arbitrary code in the context of the current process.[emaillocker id="1283"]

• CVE-2026-50058 with a CVSS score of 7.8 – An out-of-bounds read vulnerability while parsing specially crafted DFT files could allow arbitrary code execution.

• CVE-2026-50059 with a CVSS score of 7.8 – An out-of-bounds write vulnerability while parsing specially crafted DFT files could allow arbitrary code execution.

• CVE-2026-50060 with a CVSS score of 7.8 – A use-after-free vulnerability triggered while parsing specially crafted DFT files could allow arbitrary code execution.

• CVE-2026-50061 with a CVSS score of 7.8 – A use-after-free vulnerability triggered while parsing specially crafted DFT files could allow arbitrary code execution.

• CVE-2026-50062 with a CVSS score of 7.8 – An out-of-bounds read vulnerability while parsing specially crafted PAR files could allow arbitrary code execution.

• CVE-2026-50063 with a CVSS score of 7.8 – An out-of-bounds read vulnerability while parsing specially crafted PAR files could allow arbitrary code execution.

• CVE-2026-50064 with a CVSS score of 7.8 – An out-of-bounds write vulnerability while parsing specially crafted PSM files could allow arbitrary code execution.

These vulnerabilities affect Solid Edge SE2025 versions prior to V225.0.15 and Solid Edge SE2026 versions prior to V226.0.7. Exploitation requires a victim to process a specially crafted file, potentially resulting in application compromise and arbitrary code execution.

RECOMMENDATION:

We recommend you to update Siemens Solid Edge to version 225.0 or later or 226.0 or later.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu