CVE-2026-105043
Received Received - Intake

Memory Corruption in MathWorks Simulink

Vulnerability report for CVE-2026-105043, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mathworks simulink to R2026b (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-451 The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MathWorks Simulink before R2026b has a vulnerability where opening a specially crafted .slx file can cause hidden blocks in the Simulink Editor to execute code without being visible to the user.

Detection Guidance

This vulnerability involves hidden blocks in Simulink .slx files that execute code. Detection requires inspecting .slx files for unexpected blocks or scripts. Use Simulink's built-in tools to review model contents or check for unusual file modifications. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow an attacker to execute malicious code on your system by tricking you into opening a maliciously crafted .slx file. It may lead to unauthorized access, data theft, or system compromise depending on the executed code.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations using affected Simulink versions may face compliance risks if exploited.

Mitigation Strategies

Update MathWorks Simulink to R2026b or later to address the vulnerability. Avoid opening untrusted .slx files in older versions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105043. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart