CISA ICS Advisory: Siemens Parasolid
Here’s what this advisory affects, and what to do about it.
Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:intdot/ Parasolid V38.1 vers:intdot/
CISA published an Industrial Control Systems advisory on August 13, 2026, warning that Siemens Parasolid contains an out-of-bounds read vulnerability when processing X_T format files.
Watch this company
Get alerted the next time this company files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about this company’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr (indicative estimate).
Out-of-bounds read in X_T file parsing
The advisory states that Parasolid is affected by an out-of-bounds read that can be triggered when the application reads specially crafted files in X_T format. Successful exploitation could allow an attacker to crash the application or execute arbitrary code. The advisory does not state whether the vulnerability has been exploited in the wild.
Affected products
The following versions are affected:
- Parasolid V38.0 vers:intdot/
- Parasolid V38.1 vers:intdot/
No other versions or products are named in the advisory.
What to do
- Apply the updated versions of Siemens Parasolid released by the vendor.
- Determine whether any systems under your control are running Parasolid V38.0 or Parasolid V38.1.
- Restrict untrusted X_T files from reaching Parasolid-based applications until updates are applied.
- Monitor Siemens’ official product security channels for additional guidance specific to your deployment.
- Follow the full mitigation steps listed in the CISA advisory.
Organisations operating industrial control systems, engineering software suites, or medical devices that rely on Parasolid should treat this update as high priority given the potential for arbitrary code execution.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
CISA ICS Advisory: Siemens SIMATIC IoT2050 Advanced
SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing aut…
CISA ICS Advisory: PayRange API
Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated…
CISA ICS Advisory: Rently Smart Home
Successful exploitation of this vulnerability could allow an attacker to access sensitive informatio…