PatchSiren cyber security CVE debrief
CVE-2026-17061 Dassault Systèmes CVE debrief
The CVE-2026-17061 record indicates a Deserialization of Untrusted Data vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026. This vulnerability could lead to an unauthenticated remote code execution with a CVSS score of 10 and critical severity. Organizations should review the official CVE Program record and NIST NVD detail page for further information. The affected product deployments should be identified, and owners assigned for follow-up. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified.
- Vendor
- Dassault Systèmes
- Product
- SIMULIA Execution Engine
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-08-28
Who should care
Organizations using SIMULIA Execution Engine from Release 2023 through Release 2026 should prioritize patching this vulnerability to prevent potential unauthenticated remote code execution attacks. The affected operators are those who use SIMULIA Execution Engine from Release 2023 through Release 2026. The platform impact is significant, and vulnerability management and security teams should take immediate action to mitigate this vulnerability. The security teams should review the official CVE Program record and NIST NVD detail page for further information and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Technical summary
CVE-2026-17061 is a Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026. This vulnerability could lead to an unauthenticated remote code execution with a CVSS score of 10 and critical severity. The vulnerability is caused by the deserialization of untrusted data, which can allow an attacker to execute arbitrary code on the affected system. The affected product context is SIMULIA Execution Engine from Release 2023 through Release 2026. The defensive impact is significant, and defenders should take immediate action to mitigate this vulnerability.
Defensive priority
Immediate attention is required due to the critical severity and potential for unauthenticated remote code execution.
Recommended defensive actions
- Apply vendor-provided patches or updates for SIMULIA Execution Engine from Release 2023 through Release 2026.
- Restrict access to the affected system to minimize exposure.
- Monitor system logs for suspicious activity.
- Implement compensating controls such as web application firewalls.
- Perform thorough inventory checks to identify affected systems.
Evidence notes
The CVE-2026-17061 record indicates a Deserialization of Untrusted Data vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026, with a CVSS score of 10 and critical severity. Official sources include the CVE Program and NIST NVD. The evidence is limited to the information provided by these sources. Defenders should verify the affected scope, severity, and vendor guidance. The vulnerability affects SIMULIA Execution Engine from Release 2023 through Release 2026. The impact of this vulnerability is potentially significant, and defenders should take immediate action to mitigate it.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-17061 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-17061
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-17061 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17061
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.3ds.com/trust-center/security/security-advisories/cve-2026-17061
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.