HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Out‑of‑Bounds Read (CVE‑2026‑64629) in Siemens Parasolid Enables Arbitrary Code Execution

Siemens Parasolid versions prior to 38.0.235 and 38.1.230 contain an out‑of‑bounds read flaw (CVE‑2026‑64629) that could allow an attacker to execute code. For compliance teams, the vulnerability highlights the need for rigorous patch‑management evidence to satisfy SOC 2 controls.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Critical Out‑of‑Bounds Read (CVE‑2026‑64629) in Siemens Parasolid Enables Arbitrary Code Execution

What It Is — Siemens Parasolid, the geometric‑modeling kernel used in many CAD/CAM tools, contains an out‑of‑bounds read flaw when parsing specially crafted X_T files. An attacker who can supply a malicious X_T file may cause a crash or execute arbitrary code in the context of the vulnerable process.

Exploitability — Public CVE (CVE‑2026‑64629) with a CVSS 3.0 score of 7.8. No public proof‑of‑concept is known, but the vulnerability is considered exploitable by an attacker who can deliver a crafted file to the target system.

Affected Products — Siemens Parasolid V38.0 < 38.0.235 and V38.1 < 38.1.230.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 requires documented patch‑management (Control CC6.1) and evidence that critical software components are kept current.
  • An unpatched, exploitable library creates a control gap that auditors will flag during readiness assessments.
  • Continuous monitoring of third‑party component versions provides a defensible audit trail and demonstrates due‑diligence to enterprise customers.

Recommended Actions

  • Inventory every system that embeds Parasolid and verify the installed version.
  • Deploy Siemens’ patches to V38.0.235 or later and V38.1.230 or later without delay.
  • Record the patch deployment in your change‑management system and map the activity to SOC 2 Control CC6.1 (System Operations).
  • Add version‑check scripts to your continuous‑compliance platform to generate ongoing evidence of remediation.

Source: CISA Advisory – ICSA‑26‑225‑10

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-10

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →