# Siemens Parasolid Flaw Lets Attackers Execute Code via Malicious CAD Files
## The Threat
Siemens has patched a high-severity out-of-bounds read vulnerability in Parasolid, the CAD geometry kernel that sits at the heart of industrial design workflows worldwide. The flaw, tracked as CVE-2026-64629, is triggered when Parasolid parses a specially crafted file in X_T format — the native geometry exchange format used across mechanical engineering pipelines. An attacker who can deliver a malicious X_T file to a target user can crash the application or, more dangerously, execute arbitrary code in the context of the running process.
What makes this consequential is Parasolid's position in the software stack. This isn't a standalone product most engineers interact with directly — it's a licensed geometry kernel embedded in dozens of major CAD and CAM platforms, including Siemens' own NX and Solid Edge. X_T files flow freely through supplier chains, design reviews, and collaborative engineering platforms. A weaponized geometry file dropped into a procurement workflow or emailed as a design revision is a plausible and low-friction attack vector.
CISA has designated this vulnerability as affecting critical manufacturing infrastructure, with worldwide deployment exposure. The attack complexity is low: no elevated privileges are required, and the only barrier is convincing a user to open a file — something that happens dozens of times a day in any engineering shop.
## Severity and Impact
| Field | Detail |
|---|---|
| CVE | CVE-2026-64629 |
| CVSS Score | 7.8 (HIGH) |
| CVSS Version | 3.1 |
| Vector String | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Attack Vector | Local |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | Required |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
| CWE | CWE-125: Out-of-bounds Read |
| Reported By | Siemens ProductCERT to CISA |
## Affected Products
Siemens Parasolid
Both branches are affected by the same CVE. Organizations running either version without the patches are exposed.
## Mitigations
Primary remediation — patch immediately:
If patching is not immediately possible:
CISA also recommends performing a proper impact analysis and risk assessment before deploying compensating controls, particularly in OT/ICS environments where patch deployment requires change management windows.
## References
---
## HackWire Analysis
The Parasolid advisory deserves more attention than it will probably get. CAD kernel vulnerabilities tend to get quietly patched and quietly ignored — they lack the drama of ransomware or the newsworthiness of a cloud breach. But the threat model here is sharper than it looks.
Parasolid is not a product end users think about. It's infrastructure — a geometry engine licensed by Siemens to dozens of downstream ISVs. The reach of this vulnerability extends well beyond Siemens NX and Solid Edge. Any third-party CAD, simulation, or manufacturing platform that uses Parasolid under the hood and exposes X_T import is potentially in scope, and vendors have their own update cadences that may lag Siemens' patch release. That supply-chain amplification is the buried lede.
The attack path also fits a pattern we're seeing more frequently in ICS-adjacent campaigns: file-borne exploitation rather than network exploitation. You don't need to find an exposed port or bypass a firewall if you can get a mechanical engineer to open a geometry file. Spearphishing with a malicious design file — particularly one that looks like a supplier drawing, an RFQ attachment, or a revision from a known collaborator — is socially believable in a way that most phishing is not. Engineers open X_T files the way accountants open spreadsheets.
Defense teams at manufacturers, aerospace primes, and defense contractors should treat this as a file-handling hygiene wake-up call. The patch is the fix. But the broader question — whether your CAD pipeline has any controls around untrusted geometry files — is worth asking regardless of this specific CVE. Engineering data flows are often security blind spots precisely because they look like normal, boring work.
— HackWire Editorial
---
## Related Coverage