Out-of-Bounds Read in Siemens Simcenter Femap (CVE-2026-59700, CVE-2026-59701) Enables Arbitrary Code Execution
What It Is — Siemens Simcenter Femap versions prior to 2606.0001 contain two out‑of‑bounds‑read flaws in the BMP file parser. A crafted BMP can cause the application to crash or execute arbitrary code in the context of the running process.
Exploitability — No public exploit code is known, but the CVSS v3.1 base score is 7.8 (High). An attacker only needs to convince a user to open a malicious BMP, a realistic scenario in engineering environments.
Affected Products — Siemens Simcenter Femap < V2606.0001 (CVE‑2026‑59700, CVE‑2026‑59701).
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous vulnerability monitoring to satisfy SOC 2 CC6.1 (risk mitigation) and CC7.1 (system operations).
- Mapping this flaw to the “Vulnerability Management” control provides audit‑ready evidence that high‑severity findings are tracked, assessed, and remediated.
- Applying the vendor patch and documenting the change supports the Change Management control (CC6.2) required for a defensible SOC 2 audit.
Recommended Actions
- Verify your inventory for any Simcenter Femap installations and confirm they are not older than V2606.0001.
- Apply the Siemens patch (V2606.0001 or later) immediately.
- Record the remediation in your vulnerability‑management system and map it to the relevant SOC 2 control for evidence.
- Update file‑type handling policies to restrict execution of untrusted BMP files.
Source: CISA Advisory