PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44412 Siemens CVE debrief

CVE-2026-44412 is a high-severity memory corruption issue in Siemens Solid Edge affecting versions earlier than V226.0 Update 5. A specially crafted PAR file can trigger a stack-based overflow and may lead to code execution in the context of the current process.

Vendor
Siemens
Product
Solid Edge
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Administrators and users of Siemens Solid Edge, especially in engineering and industrial environments that routinely open PAR files or exchange them with external parties.

Technical summary

The advisory describes a stack-based overflow in the PAR file parser. The published CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, reflecting local attack conditions, required user interaction, and potential impact to confidentiality, integrity, and availability. Siemens lists V226.0 Update 5 or later as the fix.

Defensive priority

High

Recommended defensive actions

  • Update Siemens Solid Edge to V226.0 Update 5 or later.
  • Treat PAR files from untrusted or unverifiable sources as hazardous until the fix is applied.
  • Apply CISA and vendor-recommended industrial control and defense-in-depth practices to reduce exposure around engineering file workflows.
  • Prioritize patching on systems that regularly process externally supplied PAR files or that support higher-risk engineering workflows.

Evidence notes

The supplied CISA CSAF advisory for ICSA-26-134-03 states that affected applications contain a stack-based overflow while parsing specially crafted PAR files and that this could allow code execution in the context of the current process. The remediation entry specifies updating to V226.0 Update 5 or later. The CVSS vector in the source is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H with a score of 7.8. Timeline context: the advisory was published on 2026-05-12, received a title correction on 2026-05-13, and was republished on 2026-05-14 using the Siemens ProductCERT advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44412 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44412

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44412 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44412

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-921111.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-921111.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.