Multiple File Parsing Vulnerabilities (CVE‑2026‑50058 – CVE‑2026‑50064) in Siemens Solid Edge Pose Remote Code Execution Risk
What It Is — Siemens Solid Edge SE2025 < 225.0.15 and SE2026 < 226.0.7 contain out‑of‑bounds read/write and use‑after‑free bugs that are triggered when the application parses specially crafted PAR, PSM, or DFT files. Successful exploitation can crash the application or execute arbitrary code in the context of the current process.
Exploitability — No public exploit code has been released, but the CVSS v3.1 base score is 7.8 (High) and the flaws are remotely exploitable via malicious design files.
Affected Products — Siemens Solid Edge SE2025 and SE2026 (pre‑patch versions).
Why It Matters for Compliance & Audit Readiness
- Patch management is a core SOC 2 Control (CC7.1 Change Management); unpatched binaries break the evidence chain for a disciplined change‑control process.
- Continuous control monitoring must capture version drift across engineering workstations to prove due‑diligence.
- Demonstrating timely remediation of high‑severity CVEs is a key audit artifact for the Security and Availability principles.
Recommended Actions
- Inventory all Solid Edge installations and verify version numbers.
- Apply Siemens‑provided patches (SE2025 ≥ 225.0.15, SE2026 ≥ 226.0.7).
- Record patch deployment in your change‑management system and retain logs as audit evidence.
- Map the vulnerability to SOC 2 CC7.1 (Change Management) and CC6.1 (System Operations) controls, and enable continuous monitoring to flag future out‑of‑date CAD tools.
Source: CISA Advisory – ICSA‑26‑225‑12