PatchSiren cyber security CVE debrief
CVE-2026-44412 Siemens CVE debrief
CVE-2026-44412 is a high-severity memory corruption issue in Siemens Solid Edge affecting versions earlier than V226.0 Update 5. A specially crafted PAR file can trigger a stack-based overflow and may lead to code execution in the context of the current process.
- Vendor
- Siemens
- Product
- Solid Edge
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Administrators and users of Siemens Solid Edge, especially in engineering and industrial environments that routinely open PAR files or exchange them with external parties.
Technical summary
The advisory describes a stack-based overflow in the PAR file parser. The published CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, reflecting local attack conditions, required user interaction, and potential impact to confidentiality, integrity, and availability. Siemens lists V226.0 Update 5 or later as the fix.
Defensive priority
High
Recommended defensive actions
- Update Siemens Solid Edge to V226.0 Update 5 or later.
- Treat PAR files from untrusted or unverifiable sources as hazardous until the fix is applied.
- Apply CISA and vendor-recommended industrial control and defense-in-depth practices to reduce exposure around engineering file workflows.
- Prioritize patching on systems that regularly process externally supplied PAR files or that support higher-risk engineering workflows.
Evidence notes
The supplied CISA CSAF advisory for ICSA-26-134-03 states that affected applications contain a stack-based overflow while parsing specially crafted PAR files and that this could allow code execution in the context of the current process. The remediation entry specifies updating to V226.0 Update 5 or later. The CVSS vector in the source is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H with a score of 7.8. Timeline context: the advisory was published on 2026-05-12, received a title correction on 2026-05-13, and was republished on 2026-05-14 using the Siemens ProductCERT advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44412 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44412
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44412 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44412
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-921111.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-921111.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.