Security1 publisher3 min readPublished
Siemens patches Parasolid: a crafted X_T file is the whole attack chain
CVE-2026-64629 is an out-of-bounds read in Siemens' Parasolid, triggered by reading a file. The remediation is a version bump on two separate branches, with no listed workaround.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Parasolid is affected by an out-of-bounds read vulnerability (CVE-2026-64629) that could be triggered when the application reads files in X_T format; the flaw occurs while parsing specially crafted X_T files.
- The vulnerability could allow an attacker to crash the application or execute arbitrary code, specifically to execute code in the context of the current process.
- Affected versions are Parasolid V38.0 before V38.0.235 and Parasolid V38.1 before V38.1.230.
- Remediation is a vendor fix: update to V38.0.235 or later, or to V38.1.230 or later, via the Siemens support page at support.sw.siemens.com/product/258316782/.
- The relevant weakness is CWE-125, Out-of-bounds Read.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Siemens has released fixed builds of Parasolid for an out-of-bounds read, CVE-2026-64629, that is triggered when an application reads a file in X_T format and that can end in code execution in the context of the current process [1][2]. CISA republished the notice as an ICS advisory tagged to Critical Manufacturing and deployed worldwide, which by the advisory's own framing is a wide blast radius [6].
The affected versions are Parasolid V38.0 below V38.0.235 and V38.1 below V38.1.230 [3]. The fix is a version bump: V38.0.235 or later on the first branch, V38.1.230 or later on the second, via the Siemens support page for the product [4]. Two maintained branches, two patch levels, no single upgrade target that covers both, so an asset record that says "Parasolid 38" cannot answer the question [12]. The advisory lists no workaround or compensating control specific to the flaw, only the two vendor fixes [11].
The weakness class is CWE-125 [5]. The trigger is the part worth dwelling on: the bug fires while parsing a file, not while listening on a port [1]. The recommended practices printed on the same page are to minimize network exposure, keep control system devices off the internet, place them behind firewalls isolated from business networks, and use VPNs where remote access is required [9]. Siemens' own general recommendation is to protect network access to devices and configure the environment per its industrial security operational guidelines [10]. None of that addresses the delivery path for a file that an engineer opens on purpose [14].
The wording also matters for who does the patching. The affected product is Parasolid, but the summary describes the trigger as occurring "when the application reads files in X_T format", which distinguishes the geometry kernel from whatever calls it [15]. Remediation as written is a Parasolid version, so the practical work is establishing which tool on which engineering workstation carries which Parasolid build [4][15].
On provenance: this ICSA is a verbatim, machine-converted republication of Siemens ProductCERT advisory SSA-138516, provided "as-is", with CISA explicitly disclaiming responsibility for editorial or technical accuracy [8]. Siemens ProductCERT reported the vulnerability to CISA itself, and no external finder is credited [7]. In the material as published, the Metrics section carries no severity score [13], so a triage process that sorts by CVSS alone has nothing to sort on and will quietly drop this one.
What to watch. Whether metrics get attached later, which would change how most vulnerability management tooling treats the item [13]. Whether software that ships an embedded Parasolid build issues its own updates, since the published remediation targets Parasolid versions rather than the calling application [4][15]. And whether anything shows up in the field: CISA asks organizations observing suspected malicious activity to follow internal procedures and report findings for tracking and correlation, which is the only detection guidance on offer here [16].