Siemens Parasolid patches X_T parsing flaw
An out-of-bounds read in Siemens Parasolid's X_T file parser could let attackers crash the app or execute code; Siemens has released fixes.
Siemens has disclosed an out-of-bounds read vulnerability (CVE-2026-64629) in Parasolid, a 3D modeling engine widely used in CAD/CAM software across the critical manufacturing sector. The flaw occurs when the application parses specially crafted X_T format files, potentially allowing an attacker to crash the affected application or execute arbitrary code in the context of the current process.
The vulnerability affects Parasolid V38.0 versions prior to V38.0.235 and V38.1 versions prior to V38.1.230. Siemens has released patched versions and recommends all users update. There is no evidence of active exploitation; this is a vendor-disclosed vulnerability requiring a malicious file to be opened by a vulnerable Parasolid instance, making it a local/client-side attack vector rather than a remotely exploitable network flaw.
CISA republished the Siemens ProductCERT advisory (SSA-138516) for visibility. Organizations using Parasolid-based CAD/CAM/manufacturing software should apply the vendor patches and follow standard ICS network segmentation and hardening guidance.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-10-0
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free