VYPR
advisoryPublished Sep 1, 2026· 1 source

Two Critical Vulnerabilities Discovered in Rockwell Automation Historian ME

CISA has issued an alert detailing two critical vulnerabilities in Rockwell Automation's Historian ME software, potentially enabling remote code execution and denial-of-service conditions.

CISA has issued a new advisory highlighting two significant vulnerabilities affecting Rockwell Automation's Historian ME software, a product used across critical infrastructure sectors worldwide. The vulnerabilities, identified as CVE-2025-12768 and CVE-2026-12661, impact specific versions of the software, namely Series B 5.202 and Series C 7.101.

CVE-2025-12768 is an out-of-bounds write vulnerability. An attacker with low-level authentication could exploit this flaw to achieve remote code execution on the affected device. This could allow an adversary to take control of the system, potentially disrupting operations or exfiltrating sensitive data. The vulnerability is rated with a high CVSS v3.1 base score of 8.0, indicating a significant risk.

The second vulnerability, CVE-2026-12661, is a stack-based buffer overflow. This flaw can be exploited by a network-adjacent attacker who is authenticated. By sending crafted requests to the web interface, an attacker can trigger a buffer overflow, leading to a denial-of-service condition. This could cause the device to crash and become unresponsive, resulting in operational downtime.

These vulnerabilities affect critical infrastructure sectors including Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, and Water and Wastewater Systems. The software is deployed globally, making the potential impact widespread. Rockwell Automation has acknowledged the vulnerabilities and provided mitigation guidance for customers unable to immediately upgrade.

Customers using the affected versions are advised to consult Rockwell Automation's security best practices. While specific patched versions are not detailed in the advisory, Rockwell provides resources for mitigation and support. The company recommends contacting TechConnect for assistance or visiting their contact page for further information. For those unable to upgrade, implementing Rockwell's security best practices is crucial.

CISA strongly recommends defensive measures to minimize the risk of exploitation. These include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks behind firewalls. When remote access is necessary, secure methods like Virtual Private Networks (VPNs) should be employed, ensuring VPNs are updated and connected devices are secure.

Organizations are encouraged to perform thorough impact analyses and risk assessments before deploying any defensive measures. CISA also points to its ICS webpage for recommended cybersecurity strategies and technical information papers, such as "Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies" and "Targeted Cyber Intrusion Detection and Mitigation Strategies."

This advisory underscores the ongoing threat landscape for industrial control systems (ICS) and operational technology (OT) environments. The discovery of these vulnerabilities in widely used Rockwell Automation products highlights the persistent need for vigilance, timely patching, and robust security practices within critical infrastructure.

Synthesized by Vypr AI