Rockwell Automation Historian ME Out-of-Bounds Write and Stack-Based Buffer Overflow Vulnerabilities
First seen Sep 2, 2026 · Updated Sep 2, 2026 · CVSS 8
CISA disclosed two vulnerabilities affecting Rockwell Automation Historian ME (FactoryTalk Historian Machine Edition) Series B 5.202 and Series C 7.101. The more severe flaw (CVE-2025-12768, CVSS 8.0) allows a low-privileged authenticated attacker to achieve remote code execution via an out-of-bounds write, while the second (CVE-2026-12661, CVSS 4.5) enables a network-adjacent authenticated attacker to crash the device through a stack-based buffer overflow. No public exploitation has been reported at this time.
Technical Analysis
CVE-2025-12768 (CWE-787, Out-of-bounds Write) permits an attacker with low-level authentication and adjacent network access to execute arbitrary code on affected Historian ME devices, scoring 8.0 (CVSS v3.1) and 8.6 (CVSS v4.0). CVE-2026-12661 (CWE-121, Stack-based Buffer Overflow) allows an authenticated, network-adjacent attacker to send crafted requests to the web interface, triggering a buffer overflow that crashes the device (CVSS v3.1 4.5, CVSS v4.0 4.8). Both require adjacent network access (AV:A) and authentication, limiting remote internet-based exploitation but posing significant risk within compromised OT/IT-converged networks. These are industrial historian systems used to log and manage process data across critical manufacturing, chemical, food/agriculture, healthcare, and water/wastewater sectors, and are not typically part of AI agent tool-use stacks; however, any AI agent or automation pipeline that ingests OT data from a compromised Historian ME instance could receive corrupted or manipulated data, or an RCE on the historian host could pivot into broader OT/IT networks where agent-orchestration or monitoring tools reside, so agent-connected environments touching this data source should assess exposure.
Affected Systems
Rockwell Automation FactoryTalk Historian Machine Edition (Historian ME) Series B version 5.202; Historian ME Series C version 7.101
Indicators of Compromise
- No known IOCs; no public exploitation reported at time of disclosure.
Remediation Steps
- 1
Apply vendor mitigations
Follow Rockwell Automation's security best practices published at their support portal (answer ID 1085012) if unable to immediately upgrade affected versions.
- 2
Network segmentation
Minimize network exposure for control system devices, ensure they are not internet-accessible, and place them behind firewalls isolated from business networks.
- 3
Secure remote access
Use VPNs for remote access where required, keeping VPN software updated and recognizing that endpoint security is also critical.
- 4
Contact vendor support
Engage Rockwell Automation TechConnect or PSIRT (rasecure@ra.rockwell.com) for patching guidance and further remediation assistance.
- 5
Monitor and report
Perform risk assessments before deploying defensive measures and report any suspected malicious activity to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.