Update Siemens Simcenter Femap to version V2606.0001 or later. Apply the vendor fix available at https://support.sw.siemens.com/product/275652363/. Minimize network exposure for Simcenter Femap instances and avoid opening untrusted BMP files with the application. Follow Siemens operational guidelines for industrial security.
Quick answers
What is CVE-2026-59700?
Update Siemens Simcenter Femap to version V2606.0001 or later. Apply the vendor fix available at https://support.sw.siemens.com/product/275652363/. Minimize network exposure for Simcenter Femap instances and avoid opening untrusted BMP files with the application. Follow Siemens operational guidelines for industrial security.
How severe is CVE-2026-59700?
high, CVSS 7.8
Is CVE-2026-59700 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-59700 be mitigated?
Update Siemens Simcenter Femap to version V2606.0001 or later. Apply the vendor fix available at https://support.sw.siemens.com/product/275652363/. Minimize network exposure for Simcenter Femap instances and avoid opening untrusted BMP files with the application. Follow Siemens operational guidelines for industrial security.
CVSS
7.8
Vendor
Siemens
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Siemens Simcenter Femap
Mitigation
Update Siemens Simcenter Femap to version V2606.0001 or later. Apply the vendor fix available at https://support.sw.siemens.com/product/275652363/. Minimize network exposure for Simcenter Femap instances and avoid opening untrusted BMP files with the application. Follow Siemens operational guidelines for industrial security.
Siemens has addressed two out-of-bounds read vulnerabilities in Simcenter Femap, identified as CVE-2026-59700 and CVE-2026-59701. Both flaws stem from improper handling of specially crafted BMP files. If a user is tricked into opening such a file with an affected version of Simcenter Femap, the application may crash or an attacker could execute arbitrary code within the current process. The vulnerabilities affect versions prior to V2606.0001. Siemens has released an update and CISA has added the CVEs to its Known Exploited Vulnerabilities catalog. Exploitation requires user interaction and has not been reported in the wild as of the advisory date.