Siemens Simcenter Nastran Vulnerability Could Allow Remote Code Execution
Siemens has disclosed a security vulnerability affecting its Simcenter Nastran and Simcenter Femap engineering software, used widely across manufacturing, defense, energy, and healthcare industries. The flaw, tracked as CVE-2026-59086, is a stack-based buffer overflow that occurs when the application reads an arbitrary string as a file argument. If an attacker tricks a user into running the affected software with a malicious file or input, they could execute code on the victim's system with the same privileges as the running application.
The vulnerability carries a CVSS v3 score of 7.8, indicating a high severity risk, though it requires some form of user interaction to be exploited—such as opening a malicious file. Siemens has released updated versions of both Simcenter Femap and Simcenter Nastran to address the issue, and organisations using versions prior to 2606 should apply the update as soon as possible.
While this vulnerability primarily affects engineering and design environments in critical manufacturing and related sectors, any business using Siemens Simcenter software should treat this as a priority patching item. Attackers often rely on social engineering to get users to open malicious files, so staff awareness combined with timely software updates remains the best defence.