# Siemens Parasolid Flaw Lets Attackers Execute Code via Malicious CAD Files


## The Threat


Siemens has patched a high-severity out-of-bounds read vulnerability in Parasolid, the CAD geometry kernel that sits at the heart of industrial design workflows worldwide. The flaw, tracked as CVE-2026-64629, is triggered when Parasolid parses a specially crafted file in X_T format — the native geometry exchange format used across mechanical engineering pipelines. An attacker who can deliver a malicious X_T file to a target user can crash the application or, more dangerously, execute arbitrary code in the context of the running process.


What makes this consequential is Parasolid's position in the software stack. This isn't a standalone product most engineers interact with directly — it's a licensed geometry kernel embedded in dozens of major CAD and CAM platforms, including Siemens' own NX and Solid Edge. X_T files flow freely through supplier chains, design reviews, and collaborative engineering platforms. A weaponized geometry file dropped into a procurement workflow or emailed as a design revision is a plausible and low-friction attack vector.


CISA has designated this vulnerability as affecting critical manufacturing infrastructure, with worldwide deployment exposure. The attack complexity is low: no elevated privileges are required, and the only barrier is convincing a user to open a file — something that happens dozens of times a day in any engineering shop.


## Severity and Impact


| Field | Detail |

|---|---|

| CVE | CVE-2026-64629 |

| CVSS Score | 7.8 (HIGH) |

| CVSS Version | 3.1 |

| Vector String | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |

| Attack Vector | Local |

| Attack Complexity | Low |

| Privileges Required | None |

| User Interaction | Required |

| Confidentiality Impact | High |

| Integrity Impact | High |

| Availability Impact | High |

| CWE | CWE-125: Out-of-bounds Read |

| Reported By | Siemens ProductCERT to CISA |


## Affected Products


Siemens Parasolid


  • V38.0 — all versions prior to V38.0.235
  • V38.1 — all versions prior to V38.1.230

  • Both branches are affected by the same CVE. Organizations running either version without the patches are exposed.


    ## Mitigations


    Primary remediation — patch immediately:


  • Update Parasolid V38.0 to V38.0.235 or later
  • Update Parasolid V38.1 to V38.1.230 or later
  • Downloads and patch details: [Siemens Support Portal](https://support.sw.siemens.com/product/258316782/)

  • If patching is not immediately possible:


  • Restrict X_T file ingestion. Treat unsolicited X_T files from external parties the same way you'd treat untrusted executables. Establish a sandboxed review environment for externally sourced geometry files before opening them on networked workstations.
  • Network segmentation. Isolate engineering workstations and CAD systems from business networks. Don't expose these systems to the internet under any circumstances.
  • Disable file format auto-preview. If the host application or OS shell renders X_T thumbnails or previews automatically, disable that feature — preview rendering typically invokes the same parser.
  • VPN for remote access. Any remote access to engineering environments should go through a current, patched VPN — not direct RDP or web-based jump hosts.
  • Follow Siemens' Industrial Security Operational Guidelines: [Siemens Industrial Security](https://www.siemens.com/industrialsecurity)

  • CISA also recommends performing a proper impact analysis and risk assessment before deploying compensating controls, particularly in OT/ICS environments where patch deployment requires change management windows.


    ## References


  • [CISA ICS Advisory (ICSA-26-226-02)](https://www.cisa.gov/news-events/ics-advisories/icsa-26-226-02)
  • [Siemens ProductCERT Advisory Portal](https://www.siemens.com/cert/advisories)
  • [Siemens Parasolid Support Downloads](https://support.sw.siemens.com/product/258316782/)
  • [Siemens Industrial Security Resources](https://www.siemens.com/industrialsecurity)
  • [CISA ICS Security Recommended Practices](https://www.cisa.gov/topics/industrial-control-systems)
  • [CISA Privacy & Use Policy](https://www.cisa.gov/privacy-policy)

  • ---


    ## HackWire Analysis


    The Parasolid advisory deserves more attention than it will probably get. CAD kernel vulnerabilities tend to get quietly patched and quietly ignored — they lack the drama of ransomware or the newsworthiness of a cloud breach. But the threat model here is sharper than it looks.


    Parasolid is not a product end users think about. It's infrastructure — a geometry engine licensed by Siemens to dozens of downstream ISVs. The reach of this vulnerability extends well beyond Siemens NX and Solid Edge. Any third-party CAD, simulation, or manufacturing platform that uses Parasolid under the hood and exposes X_T import is potentially in scope, and vendors have their own update cadences that may lag Siemens' patch release. That supply-chain amplification is the buried lede.


    The attack path also fits a pattern we're seeing more frequently in ICS-adjacent campaigns: file-borne exploitation rather than network exploitation. You don't need to find an exposed port or bypass a firewall if you can get a mechanical engineer to open a geometry file. Spearphishing with a malicious design file — particularly one that looks like a supplier drawing, an RFQ attachment, or a revision from a known collaborator — is socially believable in a way that most phishing is not. Engineers open X_T files the way accountants open spreadsheets.


    Defense teams at manufacturers, aerospace primes, and defense contractors should treat this as a file-handling hygiene wake-up call. The patch is the fix. But the broader question — whether your CAD pipeline has any controls around untrusted geometry files — is worth asking regardless of this specific CVE. Engineering data flows are often security blind spots precisely because they look like normal, boring work.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)