CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Rockwell Automation Arena

criticalCVE-2026-8085CVE-2026-8312CVE-2026-8313CVE-2026-8314
View CSAF Summary Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process. The following versions of Rockwell Automation Arena are affected: Arena <=V17.00.00 (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation Arena Out-of-bounds Write Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-8085 A security issue exists within Arena Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. View CVE Details Affected Products Rockwell Automation Arena Vendor: Rockwell Automation Product Version: Rockwell Automation Arena: <=V17.00.00 Product Status: known_affected Remediations Mitigation Rockwell Automation recommends users to update to V17.00.01 Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-8312 A security issue exists within Arena Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. View CVE Details Affected Products Rockwell Automation Arena Vendor: Rockwell Automation Produc

CSIRTS triage

What
Vulnerabilities could allow arbitrary code execution in the context of the current process.
Who is affected
Users of Rockwell Automation Arena version 17.00.00 or earlier.
Urgency
Remediation is critical due to the potential for severe security breaches.
Action
Users should update to a version later than 17.00.00.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Arena

Get an email when a new Arena advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-16
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-01

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-8085coverage & exploitation statusNVD · CVE.org
CVE-2026-8312coverage & exploitation statusNVD · CVE.org
CVE-2026-8313coverage & exploitation statusNVD · CVE.org
CVE-2026-8314coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories