CVE-2026-17061: CWE-502 Deserialization of Untrusted Data in Dassault Systèmes SIMULIA Execution Engine
CVE-2026-17061 is a critical vulnerability in Dassault Systèmes SIMULIA Execution Engine from Release 2023 through Release 2026. It involves deserialization of untrusted data, which could allow unauthenticated remote code execution. The vulnerability has a CVSS score of 10. No patch or official remediation information is currently available.
AI Analysis
Technical Summary
This vulnerability, identified as CWE-502, affects the SIMULIA Execution Engine product from Dassault Systèmes in versions from Release 2023 through Release 2026. It arises from unsafe deserialization of untrusted data, enabling an attacker to execute arbitrary code remotely without authentication. The CVSS 3.1 base score is 10.0, reflecting network attack vector, no required privileges or user interaction, and complete confidentiality, integrity, and availability impact. No vendor advisory or patch information is provided at this time.
Potential Impact
Successful exploitation could lead to unauthenticated remote code execution with full system compromise, impacting confidentiality, integrity, and availability of the affected system. This represents a critical security risk for affected deployments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the SIMULIA Execution Engine and monitor for suspicious activity related to deserialization processes.
CVE-2026-17061: CWE-502 Deserialization of Untrusted Data in Dassault Systèmes SIMULIA Execution Engine
Description
CVE-2026-17061 is a critical vulnerability in Dassault Systèmes SIMULIA Execution Engine from Release 2023 through Release 2026. It involves deserialization of untrusted data, which could allow unauthenticated remote code execution. The vulnerability has a CVSS score of 10. No patch or official remediation information is currently available.
CVSS v3.1
Score 10.0critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability, identified as CWE-502, affects the SIMULIA Execution Engine product from Dassault Systèmes in versions from Release 2023 through Release 2026. It arises from unsafe deserialization of untrusted data, enabling an attacker to execute arbitrary code remotely without authentication. The CVSS 3.1 base score is 10.0, reflecting network attack vector, no required privileges or user interaction, and complete confidentiality, integrity, and availability impact. No vendor advisory or patch information is provided at this time.
Potential Impact
Successful exploitation could lead to unauthenticated remote code execution with full system compromise, impacting confidentiality, integrity, and availability of the affected system. This represents a critical security risk for affected deployments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the SIMULIA Execution Engine and monitor for suspicious activity related to deserialization processes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- 3DS
- Date Reserved
- 2026-07-24T13:46:13.875Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7b34afbf8831d539e2a60f
Added to database: 08/11/2026, 14:41:51 UTC
Last enriched: 08/11/2026, 14:59:55 UTC
Last updated: 08/11/2026, 15:01:17 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.