CVE-2026-17061
10.0Dassault Systèmes · SIMULIA Execution Engine
A deserialization of untrusted data vulnerability in the SIMULIA Execution Engine allows unauthenticated remote code execution.
Executive summary
Dassault Systèmes SIMULIA Execution Engine is vulnerable to unauthenticated remote code execution due to improper deserialization, posing a critical risk to system integrity.
Vulnerability
This is a deserialization of untrusted data flaw (CWE-502) that permits an unauthenticated remote attacker to execute arbitrary code with the privileges of the application.
Business impact
Successful exploitation allows a remote attacker to gain full control over the affected server, leading to potential data exfiltration, lateral movement, or complete system compromise. With a CVSS score of 10.0, this vulnerability represents the highest level of severity and requires immediate remediation to prevent catastrophic failure or unauthorized access to sensitive simulation data.
Remediation
Immediate Action: Update the SIMULIA Execution Engine to the latest patched release as provided in the vendor security advisory.
Proactive Monitoring: Review system access logs for anomalous network connections or unexpected process executions originating from the execution engine service.
Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the engine to trusted management workstations only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical nature of this vulnerability and the potential for total system compromise, administrators must prioritize patching the SIMULIA Execution Engine immediately. Ensure that the update is applied across all affected environments to mitigate the risk of remote exploitation.