Critical Out‑of‑Bounds Read (CVE‑2026‑64629) in Siemens Parasolid Enables Arbitrary Code Execution
What It Is — Siemens Parasolid, the geometric‑modeling kernel used in many CAD/CAM tools, contains an out‑of‑bounds read flaw when parsing specially crafted X_T files. An attacker who can supply a malicious X_T file may cause a crash or execute arbitrary code in the context of the vulnerable process.
Exploitability — Public CVE (CVE‑2026‑64629) with a CVSS 3.0 score of 7.8. No public proof‑of‑concept is known, but the vulnerability is considered exploitable by an attacker who can deliver a crafted file to the target system.
Affected Products — Siemens Parasolid V38.0 < 38.0.235 and V38.1 < 38.1.230.
Why It Matters for Compliance & Audit Readiness
- SOC 2 requires documented patch‑management (Control CC6.1) and evidence that critical software components are kept current.
- An unpatched, exploitable library creates a control gap that auditors will flag during readiness assessments.
- Continuous monitoring of third‑party component versions provides a defensible audit trail and demonstrates due‑diligence to enterprise customers.
Recommended Actions
- Inventory every system that embeds Parasolid and verify the installed version.
- Deploy Siemens’ patches to V38.0.235 or later and V38.1.230 or later without delay.
- Record the patch deployment in your change‑management system and map the activity to SOC 2 Control CC6.1 (System Operations).
- Add version‑check scripts to your continuous‑compliance platform to generate ongoing evidence of remediation.
Source: CISA Advisory – ICSA‑26‑225‑10