CVE-2026-105043: Low severity MathWorks Simulink vulnerability
Published Oct 2, 2026
·Updated
MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.
Affected Software
1 affected component
MathWorks Simulink<R2026b
Event History
Oct 2, 2026
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Simulink releases need to be reviewed for this issue?
MathWorks Simulink releases before R2026b are affected. Installations running R2026b or later are not identified as affected by the provided information.
2
What access and interaction are needed for exploitation?
The attacker needs local access and must cause a user to interact with a crafted .slx file. The CVSS vector indicates no privileges are required, but exploitation has high attack complexity and requires user interaction.