Vulnerability intelligence
CVE-2026-8312
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
CVSS Score
7
High
EPSS — Exploit Probability
0.2%
Riskier than 8% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jul 25, 2026 · latest Jul 25, 2026
Coverage timeline
-
Arena Simulation bugs allow arbitrary code execution, now patchedwww.securityweek.com · Jul 25, 2026