highOther

Rockwell Automation Historian ME Out-of-Bounds Write and Stack-Based Buffer Overflow Vulnerabilities

First seen Sep 2, 2026 · Updated Sep 2, 2026 · CVSS 8

ICSOTindustrial-control-systemsrockwell-automationfactorytalk-historianremote-code-executiondenial-of-serviceCISA-advisorycritical-infrastructure

CISA disclosed two vulnerabilities affecting Rockwell Automation Historian ME (FactoryTalk Historian Machine Edition) Series B 5.202 and Series C 7.101. The more severe flaw (CVE-2025-12768, CVSS 8.0) allows a low-privileged authenticated attacker to achieve remote code execution via an out-of-bounds write, while the second (CVE-2026-12661, CVSS 4.5) enables a network-adjacent authenticated attacker to crash the device through a stack-based buffer overflow. No public exploitation has been reported at this time.

Technical Analysis

CVE-2025-12768 (CWE-787, Out-of-bounds Write) permits an attacker with low-level authentication and adjacent network access to execute arbitrary code on affected Historian ME devices, scoring 8.0 (CVSS v3.1) and 8.6 (CVSS v4.0). CVE-2026-12661 (CWE-121, Stack-based Buffer Overflow) allows an authenticated, network-adjacent attacker to send crafted requests to the web interface, triggering a buffer overflow that crashes the device (CVSS v3.1 4.5, CVSS v4.0 4.8). Both require adjacent network access (AV:A) and authentication, limiting remote internet-based exploitation but posing significant risk within compromised OT/IT-converged networks. These are industrial historian systems used to log and manage process data across critical manufacturing, chemical, food/agriculture, healthcare, and water/wastewater sectors, and are not typically part of AI agent tool-use stacks; however, any AI agent or automation pipeline that ingests OT data from a compromised Historian ME instance could receive corrupted or manipulated data, or an RCE on the historian host could pivot into broader OT/IT networks where agent-orchestration or monitoring tools reside, so agent-connected environments touching this data source should assess exposure.

Affected Systems

Rockwell Automation FactoryTalk Historian Machine Edition (Historian ME) Series B version 5.202; Historian ME Series C version 7.101

Indicators of Compromise

  • No known IOCs; no public exploitation reported at time of disclosure.

Remediation Steps

  1. 1

    Apply vendor mitigations

    Follow Rockwell Automation's security best practices published at their support portal (answer ID 1085012) if unable to immediately upgrade affected versions.

  2. 2

    Network segmentation

    Minimize network exposure for control system devices, ensure they are not internet-accessible, and place them behind firewalls isolated from business networks.

  3. 3

    Secure remote access

    Use VPNs for remote access where required, keeping VPN software updated and recognizing that endpoint security is also critical.

  4. 4

    Contact vendor support

    Engage Rockwell Automation TechConnect or PSIRT (rasecure@ra.rockwell.com) for patching guidance and further remediation assistance.

  5. 5

    Monitor and report

    Perform risk assessments before deploying defensive measures and report any suspected malicious activity to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2025-12768CVE-2026-12661

Industries Most Exposed

ChemicalCritical ManufacturingFood and AgricultureHealthcare and Public HealthWater and Wastewater Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.