VORANT. Threat Intelligence Sign in Get the full feed

Siemens Patches Nastran Stack Overflow Flaw

routine vulnerability manufacturingdefenseenergyhealthcaretransportation

Siemens fixed a stack overflow bug in Simcenter Nastran/Femap that could let attackers run code if a user opens a malicious file argument.

Siemens has disclosed a stack-based buffer overflow vulnerability (CVE-2026-59086) affecting Simcenter Femap and Simcenter Nastran versions prior to V2606. The flaw occurs when the application binaries parse a specially crafted string passed as a file argument, and could allow an attacker to execute arbitrary code in the context of the current process if a user is tricked into running the binary with a malicious input.

This is a vendor-disclosed patch advisory with no evidence of active exploitation in the wild. Exploitation requires local user interaction (running the binary with a malicious argument), which limits the practical attack surface compared to remotely exploitable network-facing flaws. Siemens has released version V2606 to remediate the issue and recommends standard industrial network segmentation and hardening practices in the interim. The vulnerability was responsibly reported to Siemens ProductCERT by researcher Michael Heinzl.

Affected products are used across critical manufacturing, defense, energy, healthcare, and transportation sectors worldwide, reflecting the broad deployment of Siemens simulation software rather than any sector-specific targeting.

Mentioned in this report

Vulnerabilities CVE-2026-59086

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free