High severity7.3NVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
CVE-2026-8085
CVE-2026-8085
Description
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Affected products
3Patches
Vulnerability mechanics
References
1News mentions
4- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News · Jul 27, 2026
- Rockwell Patches Code Execution Flaws in Arena Simulation SoftwareSecurityWeek · Jul 25, 2026
- Rockwell Automation: 11 Vulnerabilities Disclosed, Including Critical Flaw in EtherNet/IP AdapterVypr Intelligence · Jul 16, 2026
- Rockwell Automation ArenaCISA ICS Advisories