Siemens Simcenter Nastran

2026-08-18T19:23:18Z3ba6ed305b3616d59a464488e2a09d0b550721957603296a9d124fe71d2f6e20
CVE-2026-19188CVE-2026-19670CVE-2026-19671CVE-2026-3014CVE-2026-55676CVE-2026-59086CVE-2026-59693CVE-2026-63133CVE-2026-63134CVE-2026-63177CVE-2026-65309CVE-2026-65310CVE-2026-65311CVE-2026-65313CVE-2026-69108CVE-2026-69109ANDRITZCISA ICS advisoriesCISA MalcolmHaiwellOS command injectionOT securitySiemenscritical infrastructuredenial of servicehard-coded credentialsindustrial control systemspath traversalprivilege escalationremote code executionstack overflowvulnerability management

What happened

CISA ICS advisories dated August 13–18, 2026 describe vulnerabilities affecting Siemens Simcenter Nastran, CISA Malcolm, Siemens Siveillance Video, ANDRITZ HIPASE-250/250 SCALA, Siemens Desigo controllers, Haiwell IoT Cloud HMI Gateway, and Siemens License Server. Impacts include critical OS command injection with root execution, remote code execution, stack overflow, denial of service, path traversal, unsafe archive extraction, credential exposure, missing authentication, privilege escalation, and arbitrary file access. Affected products should be upgraded to the vendor-recommended fixed or##

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
3ba6ed305b3616d59a464488e2a09d0b550721957603296a9d124fe71d2f6e20
Enrichment time
2026-08-18T19:23:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.