CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-8314

criticalCVSS 7.3covered by 2 sourcesfirst seen 2026-07-14
View CSAF Summary Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process. The following versions of Rockwell Automation Arena are affected: Arena <=V17.00.00 (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation Arena Out-of-bounds Write Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-8085 A security issue exists within Arena Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. View CVE Details Affected Products Rockwell Automation Arena Vendor: Rockwell Automation Product Version: Rockwell Automation Arena: <=V17.00.00 Product Status: known_affected Remediations Mitigation Rockwell Automation recommends users to update to V17.00.01 Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-8312 A security issue exists within Arena Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. View CVE Details Affected Products Rockwell Automation Arena Vendor: Rockwell Automation Produc

CSIRTS triage

What
Vulnerabilities could allow arbitrary code execution in the context of the current process.
Who is affected
Users of Rockwell Automation Arena version 17.00.00 or earlier.
Urgency
Remediation is critical due to the potential for severe security breaches.
Action
Users should update to a version later than 17.00.00.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-8314

Get an email if CVE-2026-8314 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-8314

CVE.org record

Embed the live status

CVE-2026-8314 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-8314 status](https://www.csirts.com/badge/CVE-2026-8314)](https://www.csirts.com/cve/CVE-2026-8314)