Security1 distinct publisher3 min readUpdated
CVE-2026-64629 is an out-of-bounds read in Siemens' Parasolid, triggered by reading a file. The remediation is a version bump on two separate branches, with no listed workaround.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Siemens has released fixed builds of Parasolid for an out-of-bounds read, CVE-2026-64629, that is triggered when an application reads a file in X_T format and that can end in code execution in the context of the current process [1][2]. CISA republished the notice as an ICS advisory tagged to Critical Manufacturing and deployed worldwide, which by the advisory's own framing is a wide blast radius [6].
The affected versions are Parasolid V38.0 below V38.0.235 and V38.1 below V38.1.230 [3]. The fix is a version bump: V38.0.235 or later on the first branch, V38.1.230 or later on the second, via the Siemens support page for the product [4]. Two maintained branches, two patch levels, no single upgrade target that covers both, so an asset record that says "Parasolid 38" cannot answer the question [12]. The advisory lists no workaround or compensating control specific to the flaw, only the two vendor fixes [11].
The weakness class is CWE-125 [5]. The trigger is the part worth dwelling on: the bug fires while parsing a file, not while listening on a port [1]. The recommended practices printed on the same page are to minimize network exposure, keep control system devices off the internet, place them behind firewalls isolated from business networks, and use VPNs where remote access is required [9]. Siemens' own general recommendation is to protect network access to devices and configure the environment per its industrial security operational guidelines [10]. None of that addresses the delivery path for a file that an engineer opens on purpose [14].
The wording also matters for who does the patching. The affected product is Parasolid, but the summary describes the trigger as occurring "when the application reads files in X_T format", which distinguishes the geometry kernel from whatever calls it [15]. Remediation as written is a Parasolid version, so the practical work is establishing which tool on which engineering workstation carries which Parasolid build [4][15].
On provenance: this ICSA is a verbatim, machine-converted republication of Siemens ProductCERT advisory SSA-138516, provided "as-is", with CISA explicitly disclaiming responsibility for editorial or technical accuracy [8]. Siemens ProductCERT reported the vulnerability to CISA itself, and no external finder is credited [7]. In the material as published, the Metrics section carries no severity score [13], so a triage process that sorts by CVSS alone has nothing to sort on and will quietly drop this one.
What to watch. Whether metrics get attached later, which would change how most vulnerability management tooling treats the item [13]. Whether software that ships an embedded Parasolid build issues its own updates, since the published remediation targets Parasolid versions rather than the calling application [4][15]. And whether anything shows up in the field: CISA asks organizations observing suspected malicious activity to follow internal procedures and report findings for tracking and correlation, which is the only detection guidance on offer here [16].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Parasolid is affected by an out-of-bounds read vulnerability (CVE-2026-64629) that could be triggered when the application reads files in X_T format; the flaw occurs while parsing specially crafted X_T files.
The vulnerability could allow an attacker to crash the application or execute arbitrary code, specifically to execute code in the context of the current process.
Affected versions are Parasolid V38.0 before V38.0.235 and Parasolid V38.1 before V38.1.230.
Remediation is a vendor fix: update to V38.0.235 or later, or to V38.1.230 or later, via the Siemens support page at support.sw.siemens.com/product/258316782/.
The advisory background lists the critical infrastructure sector as Critical Manufacturing, countries/areas deployed as Worldwide, and Siemens' company headquarters as Germany.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Authoritative but single-sourced and metric-free
Every claim comes from a first-party vendor advisory (Siemens ProductCERT SSA-138516) republished by CISA, which is high-provenance for the existence of the defect, the affected version ranges, and the fixed builds. Evidence quality is capped by the absence of any CVSS score or severity vector, no technical detail beyond CWE-125, no named host applications, and no independent corroboration in the cluster.
Fix shipped; exposure and uptake unmeasured
The one concrete adoption fact is that remediating builds exist and are downloadable, alongside a vendor statement of worldwide deployment in Critical Manufacturing. There is no installed-base figure, no patch-uptake data, no list of host applications embedding the component, and no exploitation or incident observation, so real-world exposure and remediation progress cannot be quantified.
Mildly overstated impact language, no exploitation signal
The advisory language is restrained and procedural, and the cluster framing tracks it closely. A small positive gap remains because arbitrary code execution in the current process is asserted without any CVSS score, exploitability analysis, or evidence of in-the-wild use, so the worst-case impact wording runs slightly ahead of what the supplied evidence demonstrates.
Vendor self-report; remediation is upgrade to vendor builds
Siemens ProductCERT both found and disclosed the flaw in Siemens' own product, and the sole remediation directs customers to newer vendor builds behind the Siemens support portal, so the disclosing party controls both the narrative and the fix distribution. Offsetting this, CISA republication adds a neutral distribution channel, and the advisory carries no promotional or commercial framing.
High confidence in the patch facts, low in impact and exposure
Confidence is high that the vulnerability exists, that the two branch version ranges are affected, and that fixed builds are available, because these come directly from the vendor's own advisory. Confidence is low on severity, exploitability, installed-base exposure, and which host applications are affected, since the cluster contains one source, no severity metrics, and no independent verification.
security
Siemens patches a CAE overflow that lands in the sectors that patch workstations last1 distinct publisher
build
AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure2 distinct publishers
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
The ransom is for silence now, and your restore drill does not price that1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 13, 2026