Siemens Product Family: August 2026 Regular Security Update Advisory
On August 11, 2026, Siemens released a security update addressing vulnerabilities found in several product families.
Affected Products.
- Parasolid versions earlier than V38.0.235.
- Versions of Parasolid earlier than V38.1.230.
- SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) with Industrial OS (Node-RED installation environment) versions earlier than V4.3.4.1.
- Simcenter Femap versions earlier than V2606.0001.
- Simcenter Nastran versions earlier than V2606.
- Siveillance Video versions earlier than V2023 R3 23.3.27.
- Siveillance Video versions prior to V2024 R1 24.1.16.
- Siveillance Video versions prior to V2025 25.1.15.
- Solid Edge SE2025 versions prior to V225.0.15.
- Solid Edge SE2026 versions earlier than V226.0.7.
Resolved Vulnerabilities.
- This vulnerability arises from insufficient authentication for key functions in Node-RED (a flow-based development tool used in industrial devices) on SIMATIC IoT2050 Advanced with Industrial OS. It has been classified as CVE-2026-58115 with a CVSS score of 10.0.
- An out-of-bounds read vulnerability occurring in Parasolid X_T File Parsing. Classified as CVE-2026-64629 with a CVSS score of 7.8.
- An out-of-bounds read vulnerability occurring in Simcenter Femap prior to V2606 MP1. CVE-2026-59700 and one other vulnerability have been classified with a CVSS score of 7.8.
- A stack-based buffer overflow vulnerability in Simcenter Nastran prior to version V2606. CVE-2026-59086, rated CVSS 7.8.
- This is an insufficient validation of special characters vulnerability occurring in Siveillance Video Management Servers due to inadequate validation of OS commands. CVE-2026-3014, rated CVSS 9.1.
- This is an out-of-bounds read vulnerability found in Solid Edge prior to Version SE2026 Update 7. It has been classified as CVE-2026-50058 and two others, with a CVSS score of 7.8.
- An out-of-bounds write vulnerability in Solid Edge prior to version SE2026 Update 7. Classified as CVE-2026-50059 and one other, with a CVSS score of 7.8.
- This is a use-after-free (UAF) vulnerability—a vulnerability where memory that has already been freed is reused—found in Solid Edge versions prior to SE2026 Update 7. It is classified as CVE-2026-50060 and one other, with a CVSS score of 7.8.
Recommended Actions.
Siemens recommends updating to the following versions or later:
- SIMATIC IoT2050 Advanced with Industrial OS (Node-RED installation environment) V4.3.4.1 Or later.
- Siveillance Video V2023 R3 V23.3 HotfixRev27 or later.
- Siveillance Video V2024 R1 V24.1 HotfixRev16 or later.
- Siveillance Video V2025 V25.1 HotfixRev15 or later.
- Solid Edge SE2025 V225.0 Update 15 or later.
- Solid Edge SE2026 V226.0 Update 7 or later.
- Simcenter Femap V2606.0001 Or later.
- Parasolid V38.0.235 Or later.
- Parasolid V38.1.230 Or later.
- Simcenter Nastran V2606 or later.
For more details, refer to the following documents: SSA-834709, SSA-825228, SSA-621657, SSA-584312, SSA-138516, and SSA-069220.