Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-17061RCE sin autenticación en SIMULIA Execution Engine

A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.

Ver en NVD

Análisis

Una vulnerabilidad de deserialización de datos en SIMULIA Execution Engine permite a un atacante ejecutar código de forma remota sin necesidad de autenticación previa. Este fallo afecta a las versiones de 2023 a 2026 y otorga control total sobre el servidor afectado. Se recomienda actualizar inmediatamente debido a que la vulnerabilidad alcanza la puntuación máxima de severidad.

Roles relevantes

BackendJavaCyberSecurityLinuxWindows

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-502

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.

Publicada: 11/8/2026, 15:17:27
Última modificación: 11/8/2026, 15:17:27

Referencias

InicioEventosBlogRecursosCursosEquipo