Update Siemens Parasolid to V38.0.235 or later (V38.0 branch) or V38.1.230 or later (V38.1 branch). Minimize network exposure of Parasolid-based applications. Restrict execution of untrusted X_T files. Follow Siemens operational guidelines for industrial security. Monitor CISA and Siemens advisories for updates.
Quick answers
What is CVE-2026-64629?
Update Siemens Parasolid to V38.0.235 or later (V38.0 branch) or V38.1.230 or later (V38.1 branch). Minimize network exposure of Parasolid-based applications. Restrict execution of untrusted X_T files. Follow Siemens operational guidelines for industrial security. Monitor CISA and Siemens advisories for updates.
How severe is CVE-2026-64629?
high, CVSS 7.8
Is CVE-2026-64629 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-64629 be mitigated?
Update Siemens Parasolid to V38.0.235 or later (V38.0 branch) or V38.1.230 or later (V38.1 branch). Minimize network exposure of Parasolid-based applications. Restrict execution of untrusted X_T files. Follow Siemens operational guidelines for industrial security. Monitor CISA and Siemens advisories for updates.
CVSS
7.8
Vendor
Siemens
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Siemens Parasolid
Mitigation
Update Siemens Parasolid to V38.0.235 or later (V38.0 branch) or V38.1.230 or later (V38.1 branch). Minimize network exposure of Parasolid-based applications. Restrict execution of untrusted X_T files. Follow Siemens operational guidelines for industrial security. Monitor CISA and Siemens advisories for updates.
Siemens Parasolid, a widely used 3D geometric modeling kernel, is affected by an out-of-bounds read vulnerability (CVE-2026-64629) with a CVSS score of 7.8. The flaw occurs when the application parses specially crafted X_T format files. Exploitation could allow an attacker to crash the application or execute arbitrary code in the context of the current process. Siemens has released updated versions—V38.0.235 and V38.1.230—to address the issue. The vulnerability requires local access and user interaction to trigger.