Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution.
The following versions of Rockwell Automation Historian ME are affected:
Series B 5.202 (CVE-2025-12768, CVE-2026-12661)
Series C 7.101 (CVE-2025-12768, CVE-2026-12661)
Vendor
Equipment
Rockwell Automation
Rockwell Automation Historian ME
Out-of-bounds Write, Stack-based Buffer Overflow
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, Water and Wastewater Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieveremote code execution on the affected device.
Rockwell Au...
Read the full advisory on CISA →