Siemens Simcenter Nastran
2026-08-18T19:23:18Z•3ba6ed305b3616d59a464488e2a09d0b550721957603296a9d124fe71d2f6e20
CVE-2026-19188CVE-2026-19670CVE-2026-19671CVE-2026-3014CVE-2026-55676CVE-2026-59086CVE-2026-59693CVE-2026-63133CVE-2026-63134CVE-2026-63177CVE-2026-65309CVE-2026-65310CVE-2026-65311CVE-2026-65313CVE-2026-69108CVE-2026-69109ANDRITZCISA ICS advisoriesCISA MalcolmHaiwellOS command injectionOT securitySiemenscritical infrastructuredenial of servicehard-coded credentialsindustrial control systemspath traversalprivilege escalationremote code executionstack overflowvulnerability management
What happened
CISA ICS advisories dated August 13–18, 2026 describe vulnerabilities affecting Siemens Simcenter Nastran, CISA Malcolm, Siemens Siveillance Video, ANDRITZ HIPASE-250/250 SCALA, Siemens Desigo controllers, Haiwell IoT Cloud HMI Gateway, and Siemens License Server. Impacts include critical OS command injection with root execution, remote code execution, stack overflow, denial of service, path traversal, unsafe archive extraction, credential exposure, missing authentication, privilege escalation, and arbitrary file access. Affected products should be upgraded to the vendor-recommended fixed or##
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ics_advisories
- Record identifier
- 3ba6ed305b3616d59a464488e2a09d0b550721957603296a9d124fe71d2f6e20
- Enrichment time
- 2026-08-18T19:23:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.