highOther

Siemens Parasolid Out-of-Bounds Read Vulnerability (CVE-2026-64629)

First seen Aug 14, 2026 · Updated Aug 14, 2026 · CVSS 7.8

ICSCISA-advisorySiemensout-of-bounds-readfile-parsingCVE-2026-64629critical-manufacturing

Siemens Parasolid, a 3D geometric modeling kernel used in CAD/CAM/CAE software across critical manufacturing, contains an out-of-bounds read vulnerability (CVE-2026-64629) triggered when parsing malformed X_T files. Successful exploitation could crash the application or allow arbitrary code execution in the context of the current process. Siemens has released patched versions (V38.0.235 and V38.1.230) and users are advised to update.

Technical Analysis

CVE-2026-64629 is an out-of-bounds read (CWE-125) vulnerability in Siemens Parasolid versions prior to V38.0.235 and V38.1.230, triggered when the library parses specially crafted X_T format files. Exploitation requires user interaction (opening a malicious file) and does not require elevated privileges, with CVSS 3.1 score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) reflecting high impact to confidentiality, integrity, and availability upon successful code execution. This is a local attack vector affecting the parsing engine embedded in numerous third-party CAD/CAM/CAE applications that license Parasolid, meaning exposure extends beyond Siemens-branded products to any downstream software using the vulnerable kernel. There is no direct evidence of AI agent system impact, as this vulnerability is confined to engineering/manufacturing file-parsing workflows rather than agent frameworks, LLM tool pipelines, or credential stores.

Affected Systems

Siemens Parasolid V38.0 versions prior to V38.0.235; Siemens Parasolid V38.1 versions prior to V38.1.230; any third-party CAD/CAM/CAE software embedding these Parasolid kernel versions and processing X_T format files.

Indicators of Compromise

  • No specific IOCs published; vulnerability is a file-parsing flaw exploited via crafted X_T files rather than a known active campaign with hashes/domains/IPs.

Remediation Steps

  1. 1

    Update Parasolid V38.0

    Upgrade to Parasolid V38.0.235 or later via Siemens support portal (https://support.sw.siemens.com/product/258316782/).

  2. 2

    Update Parasolid V38.1

    Upgrade to Parasolid V38.1.230 or later via Siemens support portal.

  3. 3

    Restrict file sources

    Only open X_T files from trusted, verified sources to reduce risk of exploitation via crafted malicious files.

  4. 4

    Network segmentation

    Isolate engineering workstations and ICS/OT networks running affected software from business networks and the internet per CISA general recommendations.

  5. 5

    Secure remote access

    If remote access to systems running Parasolid-based applications is required, use up-to-date VPN solutions rather than direct exposure.

CVE / Advisory IDs

CVE-2026-64629

Industries Most Exposed

Critical ManufacturingEngineeringIndustrial DesignAutomotiveAerospace

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.