Executive summary

CISA published on 18 August 2026 the advisory ICSA-26-230-02 disclosing a stack-overflow vulnerability leading to remote code execution (RCE) in Siemens Simcenter Nastran and Siemens Simcenter Femap, two engineering simulation tools widely used in the design and validation of medical devices, prosthetics, surgical instruments, and hospital equipment. The flaw lies in how the application binaries parse input strings: a user tricked into opening a malicious file or running the binary with a crafted argument can trigger RCE in the current process context. The advisory explicitly lists Healthcare and Public Health among the affected critical infrastructure sectors. CVSS v3.1 base score 7.8 (HIGH) with vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Siemens has released version V2606 as the fix.

Key points

  • Affected products: Siemens Simcenter Femap and Siemens Simcenter Nastran, versions prior to V2606 (consolidated under the same CVE-2026-59086).
  • Vulnerability: stack overflow while parsing specially crafted strings as arguments to one of the application binaries; allows code execution in the current process context.
  • CVSS v3.1 vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H → base score 7.8 (HIGH). Requires user interaction (UI:R) and local access (AV:L); no direct remote exploit, but PR:N means no prior privileges are needed.
  • CISA sectors: Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems. It is the only recent CISA advisory explicitly listing the healthcare sector.
  • Patch available: V2606 or later (Siemens Support). Siemens recommends prioritized update.
  • Advisory provenance: verbatim republication of Siemens ProductCERT SSA-069220 via CSAF.
  • Clinical risk: Simcenter Nastran/Femap are used in the design of implants, surgical instruments, orthopaedic devices, MRI/CT components, active implantable medical devices, and fluid-flow modelling for respiratory therapy equipment. Compromise of these CAD/CAE workstations can lead to exfiltration of pre-market device IP, tampering with FEM simulations (changing the outcome of a fatigue or biomechanical analysis has a direct impact on patient safety), and lateral movement into the manufacturer’s corporate network.
  • Realistic attack vector: spear-phishing a biomedical R&D engineer with a malicious .femap or .dat file, or a tampered CAE project served from a shared repository. The required user interaction is entirely credible in this environment.

Regulatory implications

FDA (US)

Medical device manufacturers using Nastran/Femap in their QMS for simulation must treat it as a design-control element (21 CFR 820.30). Compromise of the engineering workstation is a reportable event if it affects the design or verification of an authorized device (§524B(b)(2) FD&C Act — cyber device). Include the incident in the Coordinated Vulnerability Disclosure process if tampered simulation files reach the production chain.

MDR (EU)

The Medical Device Regulation applies to manufacturers using Nastran/Femap in the design or verification of MDR products. Compromise of pre-market clinical simulations obliges assessing impact on the technical documentation (Annex II). If the integrity of simulation data is compromised, conformity with Annex I (GSPR — general safety and performance requirements) may be affected. Report to the manufacturer and revalidate critical simulations if manipulation is suspected.

GDPR

If Nastran/Femap stores personal data of patients used in clinical simulations (finite-element models of real-patient anatomy, medical imaging data converted to 3D meshes, etc.), the compromise may trigger notification to the supervisory authority under Art. 33 (≤72h) if there is risk to data subjects’ rights. Special categories of Art. 9 (health data) apply when models are derived from identified patients.

NIS2 / ENS

Hospitals and device manufacturers are essential entities under NIS2 (Annex I) and critical operators under the Spanish ENS. The directive requires supply-chain risk management (Art. 21(2)(d)) — compromise of a manufacturer’s engineering tool directly impacts. In Spain, ENS category HIGH, control [op.cont.4] (supply chain management).

HIPAA

Nastran/Femap workstations in university hospitals or clinical R&D centres may contain embedded PHI (models from patient CT/MRI). If the workstation stores or processes PHI, the breach triggers §164.404 patient notification and §164.408 media notification if it exceeds 500 individuals in the same jurisdiction.

Recommendation

Immediate actions within the next 72 hours: (1) inventory all installations of Simcenter Nastran and Femap in biomedical R&D, clinical engineering and university hospital departments; (2) identify the installed version and compare against V2606 (or later); (3) apply the Siemens V2606 patch to all affected instances, prioritising those processing designs of active or implantable medical devices; (4) block the opening of .femap, .dat, .bdf and other Nastran/Femap formats from email and unapproved repositories until workstations are patched; (5) review EDR logs on CAE stations for unexpected execution of Nastran/Femap binaries or suspicious crash patterns over the last 30 days; (6) verify the integrity of critical simulations (fatigue, biomechanics, fluid dynamics) whose output has fed regulatory dossiers or design dossiers since the last potential compromise date; (7) isolate Nastran/Femap workstations on a dedicated VLAN with no Internet access, aligned with Siemens’ Industrial Security operational guidelines; (8) activate Coordinated Vulnerability Disclosure with Siemens and, where applicable, with FDA/CDRH if compromise of simulations used in premarket submissions is confirmed.


Source: CISA ICSA-26-230-02 — Siemens Simcenter Nastran

This analysis is part of HealthSec, the weekly newsletter on healthcare cybersecurity.