CVE-2026-12661
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-12768 A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieveremote code execution on the affected device. View CVE Details Affected Products Rockwell Automation Historian ME Vendor: Rockwell Automation Product Version: Rockwell Automation Series B: 5.202, Rockwell Automation Series C: 7.101 Product Status: known_affected Remediations Mitigation Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automations security best practices found at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight. https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation If you have any questions regarding the security issue(s) above and how to mitigate them, contact TechConnect for help. More information can be found at https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html. https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html Mitigation If you have any questions regarding this disclosure, please contact PSIRT Email: [email protected]
CSIRTS triage
- What
- Out-of-bounds write and stack-based buffer overflow vulnerabilities allow device crash or remote code execution.
- Who is affected
- Critical infrastructure including chemical, manufacturing, food/agriculture, healthcare, and water systems worldwide using Historian ME Series B 5.202 and Series C 7.101.
- Urgency
- Critical severity with CVSS 8.0; authenticated low-level attackers can achieve RCE via out-of-bounds writes.
- Action
- Upgrade Historian ME to patched versions; apply critical security updates from Rockwell Automation.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-12661
Get an email if CVE-2026-12661 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEW] [high] Rockwell Automation FactoryTalk Activation Manager and Historian Machine Edition: Multiple vulner…cert-bund · 2026-09-02
- unknownCVE-2026-12661: A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A net…nvd · 2026-09-01
- criticalRockwell Automation Historian MEcisa · 2026-09-01
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-12661)