PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17061 Dassault Systèmes CVE debrief

The CVE-2026-17061 record indicates a Deserialization of Untrusted Data vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026. This vulnerability could lead to an unauthenticated remote code execution with a CVSS score of 10 and critical severity. Organizations should review the official CVE Program record and NIST NVD detail page for further information. The affected product deployments should be identified, and owners assigned for follow-up. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified.

Vendor
Dassault Systèmes
Product
SIMULIA Execution Engine
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-08-28
Advisory published
2026-08-11
Advisory updated
2026-08-28

Who should care

Organizations using SIMULIA Execution Engine from Release 2023 through Release 2026 should prioritize patching this vulnerability to prevent potential unauthenticated remote code execution attacks. The affected operators are those who use SIMULIA Execution Engine from Release 2023 through Release 2026. The platform impact is significant, and vulnerability management and security teams should take immediate action to mitigate this vulnerability. The security teams should review the official CVE Program record and NIST NVD detail page for further information and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

CVE-2026-17061 is a Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026. This vulnerability could lead to an unauthenticated remote code execution with a CVSS score of 10 and critical severity. The vulnerability is caused by the deserialization of untrusted data, which can allow an attacker to execute arbitrary code on the affected system. The affected product context is SIMULIA Execution Engine from Release 2023 through Release 2026. The defensive impact is significant, and defenders should take immediate action to mitigate this vulnerability.

Defensive priority

Immediate attention is required due to the critical severity and potential for unauthenticated remote code execution.

Recommended defensive actions

  • Apply vendor-provided patches or updates for SIMULIA Execution Engine from Release 2023 through Release 2026.
  • Restrict access to the affected system to minimize exposure.
  • Monitor system logs for suspicious activity.
  • Implement compensating controls such as web application firewalls.
  • Perform thorough inventory checks to identify affected systems.

Evidence notes

The CVE-2026-17061 record indicates a Deserialization of Untrusted Data vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026, with a CVSS score of 10 and critical severity. Official sources include the CVE Program and NIST NVD. The evidence is limited to the information provided by these sources. Defenders should verify the affected scope, severity, and vendor guidance. The vulnerability affects SIMULIA Execution Engine from Release 2023 through Release 2026. The impact of this vulnerability is potentially significant, and defenders should take immediate action to mitigate it.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17061 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17061

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17061 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17061

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.