CVE-2026-23719: Siemens Simcenter Femap

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process.

Affected products

  • Siemens Simcenter Femap: before 2512.0000 (fixed in 2512.0000)
  • Siemens Simcenter Nastran: before 2512.0000 (fixed in 2512.0000)

Published 2026-02-10. Last modified 2026-06-17.