Update Siemens Solid Edge to V225.0.15 or later (SE2025) or V226.0.7 or later (SE2026). Apply patches from https://support.sw.siemens.com/product/246738425/. Restrict execution of untrusted PAR, PSM, and DFT files. Apply application whitelisting where possible.
Quick answers
What is CVE-2026-50059?
Update Siemens Solid Edge to V225.0.15 or later (SE2025) or V226.0.7 or later (SE2026). Apply patches from https://support.sw.siemens.com/product/246738425/. Restrict execution of untrusted PAR, PSM, and DFT files. Apply application whitelisting where possible.
How severe is CVE-2026-50059?
high, CVSS 7.8
Is CVE-2026-50059 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-50059 be mitigated?
Update Siemens Solid Edge to V225.0.15 or later (SE2025) or V226.0.7 or later (SE2026). Apply patches from https://support.sw.siemens.com/product/246738425/. Restrict execution of untrusted PAR, PSM, and DFT files. Apply application whitelisting where possible.
Update Siemens Solid Edge to V225.0.15 or later (SE2025) or V226.0.7 or later (SE2026). Apply patches from https://support.sw.siemens.com/product/246738425/. Restrict execution of untrusted PAR, PSM, and DFT files. Apply application whitelisting where possible.
Siemens Solid Edge computer-aided design software is affected by seven file parsing vulnerabilities disclosed August 13, 2026. The flaws — including out-of-bounds reads and writes, and use-after-free issues — reside in the handling of specially crafted files in PAR, PSM, and DFT formats. Exploitation could allow an attacker to execute arbitrary code or crash the application in the context of the current process. All seven CVEs carry a CVSS v3.1 base score of 7.8 (HIGH). Siemens has released updated versions (SE2025 V225.0.15 or later; SE2026 V226.0.7 or later) and recommends immediate updating.
Siemens Solid Edge versions SE2025 prior to V225.0.15 and SE2026 prior to V226.0.7 are affected by seven CVEs (CVE-2026-50058 through CVE-2026-50064) involving out-of-bounds read, out-of-bounds write, and use-after-free vulnerabilities in file parsing routines. The flaws are triggered when the application processes specially crafted files in PAR, PSM, or DFT format. Exploitation could allow an attacker to execute code in the context of the current process, crash the application, or potentially gain control of affected systems. CVSS v3.1 base scores are 7.8 (HIGH) for all seven vulnerabilities. Siemens has released updates and recommends immediate patching.