PatchSiren cyber security CVE debrief
CVE-2026-23717 Siemens CVE debrief
CVE-2026-23717 is a high-severity vulnerability in Siemens Simcenter Femap and Simcenter Nastran that can trigger an out-of-bounds read while parsing specially crafted XDB files. The published advisory states this could allow code execution in the context of the current process. The issue was publicly disclosed on 2026-02-10, with a CISA republication of the Siemens ProductCERT advisory on 2026-02-17. No Known Exploited Vulnerabilities (KEV) entry was supplied for this CVE.
- Vendor
- Siemens
- Product
- Simcenter Femap
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-10
- Original CVE updated
- 2026-02-17
- Advisory published
- 2026-02-10
- Advisory updated
- 2026-02-17
Who should care
Organizations using Siemens Simcenter Femap or Simcenter Nastran, especially engineering, simulation, and design teams that open XDB files from external or untrusted sources. Security teams responsible for engineering workstations should prioritize this advisory because successful exploitation may execute code in the current process.
Technical summary
The advisory describes an out-of-bounds read during parsing of specially crafted XDB files. The supplied CVSS vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates local attack conditions with required user interaction, and the impact rating reflects potential high confidentiality, integrity, and availability consequences. Siemens lists V2512 or later as the fixed version for both affected products, and also advises not opening untrusted XDB files in affected applications.
Defensive priority
High. This is a publicly disclosed code-execution-capable parsing flaw in engineering software, with user interaction required but strong impact if triggered. It is not marked as KEV in the supplied corpus, but it should still be prioritized for patching and exposure reduction on systems that handle external XDB files.
Recommended defensive actions
- Update Siemens Simcenter Femap to V2512 or later.
- Update Siemens Simcenter Nastran to V2512 or later.
- Do not open untrusted or unsolicited XDB files in affected applications.
- Restrict and review workflows that import XDB files from outside trusted engineering pipelines.
- Prioritize patching on endpoints used by design, simulation, and file-conversion personnel.
- Validate the vendor remediation guidance through the Siemens ProductCERT advisory and CISA advisory before rollout.
Evidence notes
This debrief is based only on the supplied CISA CSAF advisory metadata and the referenced Siemens ProductCERT advisory entries. The published date is 2026-02-10 and the modified/republication date is 2026-02-17, matching the supplied timeline. The corpus identifies Siemens as the vendor and Simcenter Femap plus Simcenter Nastran as the affected products. No exploitation campaign, KEV status, or additional impact details were assumed beyond the source text.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23717 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23717
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23717 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23717
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-048-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-965753.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-965753.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-048-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.