Update Siemens Simcenter Nastran and Simcenter Femap to V2606 or later versions. Protect network access to devices with appropriate mechanisms. Follow Siemens' operational guidelines for Industrial Security. Minimize network exposure and ensure control system devices are not accessible from the internet. Use firewalls and isolate control system networks from business networks.
Quick answers
What is CVE-2026-59086?
Update Siemens Simcenter Nastran and Simcenter Femap to V2606 or later versions. Protect network access to devices with appropriate mechanisms. Follow Siemens' operational guidelines for Industrial Security. Minimize network exposure and ensure control system devices are not accessible from the internet. Use firewalls and isolate control system networks from business networks.
How severe is CVE-2026-59086?
high, CVSS 7.8
Is CVE-2026-59086 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-59086 be mitigated?
Update Siemens Simcenter Nastran and Simcenter Femap to V2606 or later versions. Protect network access to devices with appropriate mechanisms. Follow Siemens' operational guidelines for Industrial Security. Minimize network exposure and ensure control system devices are not accessible from the internet. Use firewalls and isolate control system networks from business networks.
CVSS
7.8
Vendor
Siemens
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Siemens Simcenter Nastran, Simcenter Femap
Mitigation
Update Siemens Simcenter Nastran and Simcenter Femap to V2606 or later versions. Protect network access to devices with appropriate mechanisms. Follow Siemens' operational guidelines for Industrial Security. Minimize network exposure and ensure control system devices are not accessible from the internet. Use firewalls and isolate control system networks from business networks.
Siemens has identified a stack-based buffer overflow in Simcenter Nastran and Simcenter Femap that could allow remote code execution when an application binary parses a malicious string as a file argument. The vulnerability affects versions before V2606 and has been assigned CVSS v3.1 base score of 7.8 (HIGH). Siemens has released updated versions and recommends immediate updating. Exploitation requires user interaction, with no public exploit code confirmed at time of reporting.