A deserialization of untrusted data vulnerability in the SIMULIA Execution Engine allows unauthenticated remote code execution.
Description
A deserialization of untrusted data vulnerability in the SIMULIA Execution Engine allows unauthenticated remote code execution.
AI Analyst Comment
Remediation
Update Dassault Systèmes SIMULIA Execution Engine to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Dassault Systèmes
PRODUCT: SIMULIA Execution Engine
AFFECTED_VERSIONS: Release 2023 Golden, Release 2024 Golden through Release 2024 FP.CFA.2615, Release 2025 Golden through Release 2025 FP.CFA.2628, Release 2026 Golden through Release 2026 FP.CFA.2624
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A deserialization of untrusted data vulnerability in the SIMULIA Execution Engine allows unauthenticated remote code execution.
Executive Summary:
Dassault Systèmes SIMULIA Execution Engine is vulnerable to unauthenticated remote code execution due to improper deserialization, posing a critical risk to system integrity.
Vulnerability Details
CVE-ID: CVE-2026-17061
Affected Software: Dassault Systèmes SIMULIA Execution Engine
Affected Versions: Release 2023 Golden, Release 2024 Golden through Release 2024 FP.CFA.2615, Release 2025 Golden through Release 2025 FP.CFA.2628, Release 2026 Golden through Release 2026 FP.CFA.2624
Vulnerability: This is a deserialization of untrusted data flaw (CWE-502) that permits an unauthenticated remote attacker to execute arbitrary code with the privileges of the application.
Business Impact
Successful exploitation allows a remote attacker to gain full control over the affected server, leading to potential data exfiltration, lateral movement, or complete system compromise. With a CVSS score of 10.0, this vulnerability represents the highest level of severity and requires immediate remediation to prevent catastrophic failure or unauthorized access to sensitive simulation data.
Remediation Plan
Immediate Action: Update the SIMULIA Execution Engine to the latest patched release as provided in the vendor security advisory.
Proactive Monitoring: Review system access logs for anomalous network connections or unexpected process executions originating from the execution engine service.
Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the engine to trusted management workstations only.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of Aug 11, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's nature as an unauthenticated deserialization vulnerability makes it highly susceptible to weaponization.
Analyst Recommendation
Given the critical nature of this vulnerability and the potential for total system compromise, administrators must prioritize patching the SIMULIA Execution Engine immediately. Ensure that the update is applied across all affected environments to mitigate the risk of remote exploitation.