# Siemens Femap patches BMP parsing flaws

Published: 2026-08-13 · Severity: routine · Sectors: manufacturing
Canonical: https://vorant.io/reports/46aa9b6f-453a-594b-934e-1af77e292843/siemens-femap-patches-bmp-parsing-flaws

> Two out-of-bounds read vulnerabilities in Siemens Simcenter Femap's BMP file parsing could allow arbitrary code execution via malicious files.

Siemens has patched two out-of-bounds read vulnerabilities (CVE-2026-59700 and CVE-2026-59701) in Simcenter Femap, its finite element analysis software used in critical manufacturing environments worldwide. Both flaws stem from improper bounds checking when the application parses specially crafted BMP image files, and could cause a crash or potentially allow an attacker to execute arbitrary code in the context of the current process if a user is tricked into opening a malicious file.

The vulnerabilities affect all versions of Simcenter Femap prior to V2606.0001. Siemens ProductCERT reported the issues to CISA, and a fix is available by updating to the patched version. There is no evidence of active exploitation; this is a standard vendor-disclosed vulnerability advisory requiring a local file-based attack vector (social engineering to open a malicious BMP file), rather than a remotely exploitable network flaw.

CISA republished the Siemens advisory as part of its routine ICS vulnerability disclosure process, recommending standard mitigations such as minimizing network exposure of control system devices, isolating ICS networks behind firewalls, and using secure remote access methods like VPNs where necessary.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59700, CVE-2026-59701

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-11

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/46aa9b6f-453a-594b-934e-1af77e292843/siemens-femap-patches-bmp-parsing-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
