PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23719 Siemens CVE debrief

CVE-2026-23719 is a high-severity heap-based buffer overflow affecting Siemens Simcenter Femap and Simcenter Nastran when parsing specially crafted NDB files. A successful attack could allow code execution in the context of the current process, so organizations should treat any workflow that opens untrusted NDB files as exposed until patched.

Vendor
Siemens
Product
Simcenter Femap
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-10
Original CVE updated
2026-02-17
Advisory published
2026-02-10
Advisory updated
2026-02-17

Who should care

Administrators, engineers, and users of Siemens Simcenter Femap or Simcenter Nastran—especially environments where NDB files may come from outside the organization or from untrusted sources.

Technical summary

According to the CISA CSAF advisory and Siemens product security advisory, the flaw is a heap-based buffer overflow triggered during NDB file parsing. The CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local access with user interaction required. The stated impact is code execution in the context of the current process.

Defensive priority

High. The issue is rated CVSS 7.8 and has a plausible path to code execution if a user opens a malicious NDB file, so patching should be prioritized for affected systems that handle external or untrusted files.

Recommended defensive actions

  • Update Siemens Simcenter Femap to V2512 or later.
  • Update Siemens Simcenter Nastran to V2512 or later.
  • Do not open untrusted or suspicious NDB files in affected applications.
  • Review file-handling workflows to limit exposure to externally supplied engineering files.
  • Follow Siemens ProductCERT and CISA advisory guidance for any additional product-specific mitigations.

Evidence notes

The source corpus identifies Siemens as the vendor and Simcenter Femap plus Simcenter Nastran as the affected products. CISA published the advisory on 2026-02-10 and republished it on 2026-02-17 after initial republication of Siemens ProductCERT advisory SSA-965753. The remediation guidance in the source explicitly recommends updating both products to V2512 or later and avoiding untrusted NDB files.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23719 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23719

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23719 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23719

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-048-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-965753.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-965753.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-048-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.