Security/ siemens · ics-security · cisa · vulnerability

Siemens Patches Femap Flaws That Let Malicious BMPs Run Code

Two out-of-bounds read flaws in Siemens Femap's BMP image parser can crash the engineering CAD tool or run attacker code, and updating is the only fix.

Siemens has a fix for two bugs in its Simcenter Femap engineering software that could let a booby-trapped image file take over your machine.

CISA has republished a Siemens advisory disclosing two out-of-bounds read vulnerabilities, tracked as CVE-2026-59700 and CVE-2026-59701, in Simcenter Femap, a CAD tool used for finite element analysis. Both bugs live in how the software parses BMP image files: open a malicious BMP and Femap can crash, or let an attacker run their own code with the privileges of whoever opened the file. Each flaw carries a CVSS score of 7.8, rated high severity. Siemens fixed the issue in version 2606.0001 and wants every customer on an older build to update.

Femap isn't consumer software. It's used by engineers in critical manufacturing to model and simulate physical parts, so a compromised workstation could sit inside the same network as production systems. The bug needs a user to open the file rather than working over a network connection alone, which makes this a phishing-style risk more than a remote one, but that's cold comfort in an industry where engineers routinely trade design files with vendors and clients.

It's the familiar industrial-software pattern: file parsers written years ago are only now getting scrutinized with modern fuzzing tools, and the remedy is the same as always - update the software, and keep it off the open internet in the meantime.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →