Rockwell Automation Historian ME
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-12768 A security issue exists within FactoryTalk Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device. View CVE Details Affected Products Rockwell Automation Historian ME Vendor: Rockwell Automation Product Version: Rockwell Automation Series B: 5.202, Rockwell Automation Series C: 7.101 Product Status: known_affected Remediations Mitigation Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automations security best practices found at: https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation If you have any questions regarding the security issue(s) above and how to mitigate them, contact TechConnect for help. More information can be found at: https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html Mitigation If you have any questions regarding this disclosure, please contact PSIRT Email: [email protected] Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 8 HIGH CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.6
CSIRTS triage
- What
- Out-of-bounds write and stack-based buffer overflow vulnerabilities allow device crash or remote code execution.
- Who is affected
- Critical infrastructure including chemical, manufacturing, food/agriculture, healthcare, and water systems worldwide using Historian ME Series B 5.202 and Series C 7.101.
- Urgency
- Critical severity with CVSS 8.0; authenticated low-level attackers can achieve RCE via out-of-bounds writes.
- Action
- Upgrade Historian ME to patched versions; apply critical security updates from Rockwell Automation.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Historian ME
Get an email when a new Historian ME advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-127680.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-126610.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-12768 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12661 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Rockwell Automation Historian
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.