CVE-2026-50060: Use After Free
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Solid Edge SE2025to a version that resolves this vulnerability.Fixed in V225.0 Update 15 - Upgrade
Upgrade
Solid Edge SE2026to a version that resolves this vulnerability.Fixed in V226.0 Update 7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50060?
The severity of CVE-2026-50060 is high, with a CVSS score of 7.8.
How do I fix CVE-2026-50060?
To fix CVE-2026-50060, update to Solid Edge SE2025 version V225.0 Update 15 or later and Solid Edge SE2026 version V226.0 Update 7 or later.
What products are affected by CVE-2026-50060?
The affected products include Siemens Solid Edge SE2025 versions prior to V225.0 Update 15 and Siemens Solid Edge SE2026 versions prior to V226.0 Update 7.
What type of vulnerability is CVE-2026-50060?
CVE-2026-50060 is identified as a use-after-free vulnerability.
What could happen if CVE-2026-50060 is exploited?
Exploitation of CVE-2026-50060 could allow an attacker to execute arbitrary code due to the use-after-free condition while parsing specially crafted DFT files.