VORANT. Threat Intelligence Sign in Get the full feed

Siemens Femap patches BMP parsing flaws

routine vulnerability manufacturing

Two out-of-bounds read vulnerabilities in Siemens Simcenter Femap's BMP file parsing could allow arbitrary code execution via malicious files.

Siemens has patched two out-of-bounds read vulnerabilities (CVE-2026-59700 and CVE-2026-59701) in Simcenter Femap, its finite element analysis software used in critical manufacturing environments worldwide. Both flaws stem from improper bounds checking when the application parses specially crafted BMP image files, and could cause a crash or potentially allow an attacker to execute arbitrary code in the context of the current process if a user is tricked into opening a malicious file.

The vulnerabilities affect all versions of Simcenter Femap prior to V2606.0001. Siemens ProductCERT reported the issues to CISA, and a fix is available by updating to the patched version. There is no evidence of active exploitation; this is a standard vendor-disclosed vulnerability advisory requiring a local file-based attack vector (social engineering to open a malicious BMP file), rather than a remotely exploitable network flaw.

CISA republished the Siemens advisory as part of its routine ICS vulnerability disclosure process, recommending standard mitigations such as minimizing network exposure of control system devices, isolating ICS networks behind firewalls, and using secure remote access methods like VPNs where necessary.

Mentioned in this report

Vulnerabilities CVE-2026-59700CVE-2026-59701

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-11

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free