Siemens Product Family: August 2026 Regular Security Update Advisory

Siemens Product Family: August 2026 Regular Security Update Advisory

On August 11, 2026, Siemens released a security update addressing vulnerabilities found in several product families.

Affected Products.

  • Parasolid versions earlier than V38.0.235.
  • Versions of Parasolid earlier than V38.1.230.
  • SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) with Industrial OS (Node-RED installation environment) versions earlier than V4.3.4.1.
  • Simcenter Femap versions earlier than V2606.0001.
  • Simcenter Nastran versions earlier than V2606.
  • Siveillance Video versions earlier than V2023 R3 23.3.27.
  • Siveillance Video versions prior to V2024 R1 24.1.16.
  • Siveillance Video versions prior to V2025 25.1.15.
  • Solid Edge SE2025 versions prior to V225.0.15.
  • Solid Edge SE2026 versions earlier than V226.0.7.

Resolved Vulnerabilities.

  • This vulnerability arises from insufficient authentication for key functions in Node-RED (a flow-based development tool used in industrial devices) on SIMATIC IoT2050 Advanced with Industrial OS. It has been classified as CVE-2026-58115 with a CVSS score of 10.0.
  • An out-of-bounds read vulnerability occurring in Parasolid X_T File Parsing. Classified as CVE-2026-64629 with a CVSS score of 7.8.
  • An out-of-bounds read vulnerability occurring in Simcenter Femap prior to V2606 MP1. CVE-2026-59700 and one other vulnerability have been classified with a CVSS score of 7.8.
  • A stack-based buffer overflow vulnerability in Simcenter Nastran prior to version V2606. CVE-2026-59086, rated CVSS 7.8.
  • This is an insufficient validation of special characters vulnerability occurring in Siveillance Video Management Servers due to inadequate validation of OS commands. CVE-2026-3014, rated CVSS 9.1.
  • This is an out-of-bounds read vulnerability found in Solid Edge prior to Version SE2026 Update 7. It has been classified as CVE-2026-50058 and two others, with a CVSS score of 7.8.
  • An out-of-bounds write vulnerability in Solid Edge prior to version SE2026 Update 7. Classified as CVE-2026-50059 and one other, with a CVSS score of 7.8.
  • This is a use-after-free (UAF) vulnerability—a vulnerability where memory that has already been freed is reused—found in Solid Edge versions prior to SE2026 Update 7. It is classified as CVE-2026-50060 and one other, with a CVSS score of 7.8.

Recommended Actions.

Siemens recommends updating to the following versions or later:

  • SIMATIC IoT2050 Advanced with Industrial OS (Node-RED installation environment) V4.3.4.1 Or later.
  • Siveillance Video V2023 R3 V23.3 HotfixRev27 or later.
  • Siveillance Video V2024 R1 V24.1 HotfixRev16 or later.
  • Siveillance Video V2025 V25.1 HotfixRev15 or later.
  • Solid Edge SE2025 V225.0 Update 15 or later.
  • Solid Edge SE2026 V226.0 Update 7 or later.
  • Simcenter Femap V2606.0001 Or later.
  • Parasolid V38.0.235 Or later.
  • Parasolid V38.1.230 Or later.
  • Simcenter Nastran V2606 or later.

For more details, refer to the following documents: SSA-834709, SSA-825228, SSA-621657, SSA-584312, SSA-138516, and SSA-069220.