Critical Remote Code Execution Flaw in SIMULIA Execution Engine Exposes Defense and Enterprise Systems to Zero-Logon Attacks
Overview
CVE-2026-17061 represents an unprecedented risk due to its CVSS 10.0 severity score, enabling unauthenticated attackers to execute arbitrary code on vulnerable SIMULIA Execution Engine instances. This exploit requires no user interaction or credentials, allowing direct system compromise for any network-connected threat actor.
Technical Analysis
The vulnerability stems from unsafe deserialization of unauthenticated input in the SIMULIA Execution Engine's service interface. Attackers can construct malicious Java/Python serialization payloads that bypass type-safety checks, leading to arbitrary object instantiation and code execution. The exposed service endpoint (typically TCP/19121) is accessible by default without authentication, enabling straightforward exploitation using commodity tools like ysoserial or Pyserial.
Enterprise & DIB Impact
DIB organizations and enterprises relying on SIMULIA for CAE/FEA simulations face catastrophic risks from this flaw. Compromise of these systems could reveal sensitive defense contracts, intellectual property, or operational data. The unauthenticated nature of the exploit removes a critical security layer, making traditional access controls ineffective against this vector.
Recommended Actions
- Apply the Dassault Systèmes patch (Ref. DS-2026-SEE-02) immediately
- disable the SIMULIA Execution Engine service if unused
- configure network segmentation to isolate critical simulation workloads
- monitor for unexpected outbound connections from affected hosts
- deploy intrusion prevention rules blocking suspicious serialization patterns on port 19121
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →