Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · rockwellautomation

rockwellautomation

· 63 Critical

Total CVEs

345

Critical

63

Products

472

Search All CVEs →

345

Products (472)

arena42 CVEsmicrologix 140028 CVEsmicrologix 1400 b firmware22 CVEsfactorytalk view18 CVEsthinmanager16 CVEscontrollogix 558014 CVEsguardlogix 558014 CVEsmicrologix 1100 firmware14 CVEsfactorytalk linx14 CVEsfactorytalk services platform13 CVEscompactlogix 538013 CVEscontrollogix 5580 firmware13 CVEsguardlogix 5580 firmware13 CVEscompactlogix 548012 CVEscompactlogix 5380 firmware12 CVEsfactorytalk assetcentre12 CVEsmicrologix 1400 firmware11 CVEscompactlogix 5480 firmware11 CVEsmicrologix 110010 CVEsarmorstart st 281e10 CVEsarmorstart st 281e firmware10 CVEsarmorstart st 284ee10 CVEsarmorstart st 284ee firmware10 CVEs1756-enbt9 CVEscompact guardlogix 53809 CVEsrslinx9 CVEsarmorstart lt firmware9 CVEsarmorstart lt9 CVEskepserver enterprise9 CVEs1756-eweb8 CVEs1763-l16bwa series a8 CVEs1763-l16bbb series b8 CVEs1768-enbt8 CVEscompact guardlogix 5380 firmware8 CVEs1768-eweb8 CVEs1763-l16awa series b8 CVEs1763-l16dwd series a8 CVEs1763-l16awa series a8 CVEs1763-l16bwa series b8 CVEs1763-l16bbb series a8 CVEs1763-l16dwd series b8 CVEsab micrologix controller8 CVEs1766-l32awa series b7 CVEscompactlogix controllers7 CVEs1766-l32bxb series a7 CVEs1766-l32bwa series a7 CVEs1766-l32bwaa series b7 CVEs1766-l32bwa series b7 CVEsflexlogix 1788-enbt adapter7 CVEs1766-l32bwaa series a7 CVEscompactlogix l32e controller7 CVEscompactlogix l35e controller7 CVEscontrollogix7 CVEssoftlogix7 CVEsrslinx enterprise7 CVEs1794-aentr flex i\/o ethernet\/ip adapter7 CVEscontrollogix controllers7 CVEs1766-l32awa series a7 CVEssoftlogix controllers7 CVEsmicrologix7 CVEs1766-l32bxba series b7 CVEs1766-l32bxba series a7 CVEsguardlogix controllers7 CVEscompactlogix7 CVEs1766-l32awaa series a7 CVEs1766-l32awaa series b7 CVEs1766-l32bxb series b7 CVEsguardlogix7 CVEscompact guardlogix 53706 CVEsrslinx classic6 CVEsconnected components workbench6 CVEsmicro8305 CVEsallen-bradley stratix 54005 CVEsallen-bradley stratix 54105 CVEsallen-bradley stratix 57005 CVEsallen-bradley stratix 80005 CVEscontrollogix 55705 CVEscompact guardlogix 5370 firmware5 CVEs1756-en2tr series a5 CVEs1756-en2tr series a firmware5 CVEsfactorytalk policy manager5 CVEsguardlogix 55705 CVEsisagraf free runtime5 CVEsisagraf runtime5 CVEs1756-en2tr series b5 CVEs1756-en2tr series b firmware5 CVEs1756-en2tr series c5 CVEs1756-en2tr series c firmware5 CVEsmicro8105 CVEsmicro810 firmware5 CVEsmicro8205 CVEsmicro820 firmware5 CVEscompactlogix 5370 l3 firmware5 CVEsmicro830 firmware5 CVEsmicro8505 CVEsmicro850 firmware5 CVEsmicro8705 CVEsmicro870 firmware5 CVEs1756-en4tr5 CVEs1756-en4tr firmware5 CVEsmicrologix 1400 a firmware5 CVEspavilion85 CVEsrslogix 5005 CVEsaadvance controller5 CVEsallen-bradley armorstratix 57005 CVEscompactlogix 5370 l15 CVEscompactlogix 5370 l1 firmware5 CVEscompactlogix 5370 l25 CVEscompactlogix 5370 l2 firmware5 CVEscompactlogix 5370 l35 CVEsthinmanager thinserver5 CVEsallen-bradley stratix 83004 CVEscompact guardlogix 5380 sil 24 CVEsisagraf workbench4 CVEscompact guardlogix 5380 sil 2 firmware4 CVEsstudio 5000 logix designer4 CVEscompact guardlogix 5380 sil 34 CVEscompact guardlogix 5380 sil 3 firmware4 CVEsguardlogix 5570 firmware4 CVEsfactorytalk system services4 CVEscontrollogix 5570 firmware4 CVEs1756-en3tr series b firmware3 CVEsthinserver3 CVEs1756-en2f series a3 CVEscontrollogix 1756-enbt\/a ethernet\/ ip bridge3 CVEsarmor compact guardlogix 5370 firmware3 CVEsarmor compact guardlogix 53703 CVEscompactlogix 53703 CVEs1756-en2t series b3 CVEs1756-en2t series b firmware3 CVEs1756-en4trxt3 CVEs1756-en4trxt firmware3 CVEs1783-natr3 CVEs1783-natr firmware3 CVEs1756-en2t series c3 CVEs1756-en2t series c firmware3 CVEs1756-en2t series d3 CVEs1756-en2f series a firmware3 CVEs1756-en2t series d firmware3 CVEs1756-en2f series b3 CVEs1756-en2f series b firmware3 CVEspowerflex 527 ac drives3 CVEspowerflex 527 ac drives firmware3 CVEs1756-en2f series c3 CVEs1756-en2f series c firmware3 CVEspowermonitor 10003 CVEspowermonitor 1000 firmware3 CVEs1756-en2t series a3 CVEs1756-en3tr series a3 CVEsfactorytalk vantagepoint3 CVEs1756-en3tr series a firmware3 CVEsrslogix 50003 CVEs1756-en3tr series b3 CVEs1756-en2t series a firmware3 CVEsrslogix micro developer2 CVEs1766-l32awaa2 CVEs1756-en4 firmware2 CVEsfactorytalk alarms and events2 CVEs1766-l32bxba2 CVEs1734-aentr point i\/o dual port network adaptor series b firmware2 CVEs1756-en42 CVEsrsnetworx2 CVEscontrollogix 5570 controller firmware2 CVEscontrollogix 5570 controller2 CVEsrslogix2 CVEssafety instrumented systems workstation2 CVEscontrollogix 55502 CVEs1734-aentr point i\/o dual port network adaptor series c firmware2 CVEs1734-aentr point i\/o dual port network adaptor series b2 CVEs1766-l32awa2 CVEsflex i\/o 1794-aent\/b firmware2 CVEsdrivelogix 57302 CVEs1766-l32bwaa2 CVEssoftlogix 58002 CVEseds subsystem2 CVEscontrollogix 5580 process firmware2 CVEsflex i\/o 1794-aent\/b2 CVEsflex i\/o 1794-aent2 CVEsallen-bradley stratix 59002 CVEs1766-l32bxb2 CVEs1734-aentr point i\/o dual port network adaptor series c2 CVEscontrollogix 5580 process2 CVEscompactlogix 5370 firmware2 CVEscontrollogix 5570 redundant controller firmware2 CVEscontrollogix 5570 redundant controller2 CVEsrslogix micro starter lite2 CVEs1766-l32bwa2 CVEsfactorytalk energrymetrix2 CVEsguardlogix 55602 CVEsallen-bradley stratix 8300 industrial managed ethernet switch2 CVEsguardlogix 5560 firmware2 CVEscontrollogix 55602 CVEsfactorytalk2 CVEsguardlogix 5570 controller2 CVEsguardlogix 5570 controller firmware2 CVEs5015-aenftxt2 CVEs5015-aenftxt firmware2 CVEsembedded edge compute module firmware1 CVEsenhanced him1 CVEsethernet\/ip firmware1 CVEsethernet\/ip web server module 1756-eweb1 CVEsethernet\/ip web server module 1768-eweb1 CVEsfactorytalk activation1 CVEsfactorytalk activation manager1 CVEsfactorytalk analytics logixai1 CVEsfactorytalk batch view1 CVEsfactorytalk diagnostics1 CVEsfactorytalk diagnostics viewer1 CVEsfactorytalk linx gateway1 CVEsfactorytalk logix echo1 CVEsfactorytalk logix echo firmware1 CVEsfactorytalk optix1 CVEsfactorytalk transaction manager1 CVEsfactorytalk view studio1 CVEsflex i\/o ethernet\/ip firmware1 CVEsflex io 1794-aent\/b1 CVEsflex io 1794-aent\/b firmware1 CVEsflexlogix 1794-l341 CVEsflexlogix 1794-l34 firmware1 CVEsflexlogix firmware1 CVEsflexlogix l34 controller1 CVEsflexlogix l34 controller firmware1 CVEsguardlogix controllers firmware1 CVEsguardlogix firmware1 CVEsintegrated architecture builder1 CVEsisagraf1 CVEskinetix 55001 CVEskinetix 5500 firmware1 CVEskinetix 57001 CVEskinetix 5700 firmware1 CVEsl32e1 CVEsl35e1 CVEslogix 5000 controller1 CVEsmicro8001 CVEsmicro800 firmware1 CVEsmicrologix 1100 b firmware1 CVEsmicrologix 1400-a1 CVEsmicrologix 1400-a firmware1 CVEsmicrologix 1400-b1 CVEsmicrologix 1400-b firmware1 CVEs11001 CVEsmicrologix 1400-c firmware1 CVEsmicrologix firmware1 CVEsmodbus tcp server add on instructions1 CVEspanelview 55101 CVEspanelview 5510 firmware1 CVEspanelview plus1 CVEspanelview plus 6 700-15001 CVEspanelview plus 6 700-1500 firmware1 CVEsplc-5 controller1 CVEsplc5 1785-lx1 CVEsplc5 1785-lx firmware1 CVEspowerflex 525 ac drives1 CVEspowerflex 525 ac drives firmware1 CVEspowerflex 6000t1 CVEspowerflex 6000t firmware1 CVEsrslogix 51 CVEsrslogix 5000 design and configuration software1 CVEsrslogix 500 professional edition1 CVEsrslogix 500 standard edition1 CVEsrslogix 500 starter edition1 CVEsrslogix emulate 50001 CVEsrslogix emulate 5000 firmware1 CVEsrsview321 CVEssequencemanager1 CVEsslc5\/01 1747-l5x1 CVEsslc5\/01 1747-l5x firmware1 CVEsslc 500 controller1 CVEssoftlogix 5800 controller1 CVEssoftlogix 5800 controller firmware1 CVEssoftlogix 5800 firmware1 CVEssoftlogix controllers firmware1 CVEssoftlogix firmware1 CVEsstratix 59001 CVEsstudio 5000 logix emulate1 CVEsmicrologix 1400-c1 CVEs14001 CVEs1756-en2fk series a1 CVEs1756-en2fk series a firmware1 CVEs1756-en2fk series b1 CVEs1756-en2fk series b firmware1 CVEs1756-en2fk series c1 CVEs1756-en2fk series c firmware1 CVEs1756-en2tk series a1 CVEs1756-en2tk series a firmware1 CVEs1756-en2tk series b1 CVEs1756-en2tk series b firmware1 CVEs1756-en2tk series c1 CVEs1756-en2tk series c firmware1 CVEs1756-en2tp series a1 CVEs1756-en2tp series a firmware1 CVEs1756-en2tpk series a1 CVEs1756-en2tpk series a firmware1 CVEs1756-en2tpxt series a1 CVEs1756-en2tpxt series a firmware1 CVEs1756-en2trk series a1 CVEs1756-en2trk series a firmware1 CVEs1756-en2trk series b1 CVEs1756-en2trk series b firmware1 CVEs1756-en2trk series c1 CVEs1756-en2trk series c firmware1 CVEs1756-en2trxt series a1 CVEs1756-en2trxt series a firmware1 CVEs1756-en2trxt series b1 CVEs1756-en2trxt series b firmware1 CVEs1756-en2trxt series c1 CVEs1756-en2trxt series c firmware1 CVEs1756-en2txt series a1 CVEs1756-en2txt series a firmware1 CVEs1756-en2txt series b1 CVEs1756-en2txt series b firmware1 CVEs1756-en2txt series c1 CVEs1756-en2txt series c firmware1 CVEs1756-en2txt series d1 CVEs1756-en2txt series d firmware1 CVEs1756-en3trk series a1 CVEs1756-en3trk series a firmware1 CVEs1756-en3trk series b1 CVEs1756-en3trk series b firmware1 CVEs1756-en4trk1 CVEs1756-en4trk firmware1 CVEs1756-enbt\/a1 CVEs1756-enbt\/a firmware1 CVEs1756-enbt firmware1 CVEs1756-eweb series a1 CVEs1756-eweb series a firmware1 CVEs1756-eweb series b1 CVEs1756-eweb series b firmware1 CVEs1763-l16awa1 CVEs1763-l16awa firmware1 CVEs1763-l16bbb1 CVEs1763-l16bbb firmware1 CVEs1763-l16bwa1 CVEs1763-l16bwa firmware1 CVEs1763-l16dwd1 CVEs1763-l16dwd firmware1 CVEs1766-l32awa firmware1 CVEs1766-l32awaa firmware1 CVEs1766-l32bwa firmware1 CVEs1766-l32bwaa firmware1 CVEs1766-l32bxb firmware1 CVEs1766-l32bxba firmware1 CVEs1768 compact guardlogix l4xs controller1 CVEs1768 compact guardlogix l4xs controller firmware1 CVEs1768 compactlogix l4x controller1 CVEs1768 compactlogix l4x controller firmware1 CVEs1769 compactlogix 5370 l1 controller1 CVEs1769 compactlogix 5370 l1 controller firmware1 CVEs1769 compactlogix 5370 l2 controller1 CVEs1769 compactlogix 5370 l2 controller firmware1 CVEs1769 compactlogix 5370 l3 controller1 CVEs1769 compactlogix 5370 l3 controller firmware1 CVEs1769 compactlogix l23x controller1 CVEs1769 compactlogix l23x controller firmware1 CVEs1769 compactlogix l3x controller1 CVEs1769 compactlogix l3x controller firmware1 CVEs1788-enbt1 CVEs1794-aentr1 CVEs2800c optixpanel compact1 CVEs2800c optixpanel compact firmware1 CVEs2800s optixpanel standard1 CVEs2800s optixpanel standard firmware1 CVEs5015-u8ihft1 CVEs5015-u8ihft firmware1 CVEs9328-ccwdevdee1 CVEs9328-ccwdevene1 CVEs9328-ccwdevese1 CVEs9328-ccwdevfre1 CVEs9328-ccwdevite1 CVEs9328-ccwdevpte1 CVEs9328-ccwdevzhe1 CVEsab micrologix controller 11001 CVEsab micrologix controller 14001 CVEsallen-bradley flex io 1794-aent\/b1 CVEsallen-bradley flex io 1794-aent\/b firmware1 CVEsallen-bradley l30erms1 CVEsallen-bradley l30erms firmware1 CVEsallen-bradley stratix 52001 CVEsallen-bradley stratix 5200 firmware1 CVEsallen-bradley stratix 58001 CVEsallen-bradley stratix 5800 firmware1 CVEsallen-bradley stratix 5900 services router1 CVEsarmor powerflex1 CVEsarmor powerflex firmware1 CVEscompactlogix 1756-en2f series a1 CVEscompactlogix 1756-en2f series a firmware1 CVEscompactlogix 1756-en2f series b1 CVEscompactlogix 1756-en2f series b firmware1 CVEscompactlogix 1756-en2t series a1 CVEscompactlogix 1756-en2t series a firmware1 CVEscompactlogix 1756-en2t series b1 CVEscompactlogix 1756-en2t series b firmware1 CVEscompactlogix 1756-en2t series c1 CVEscompactlogix 1756-en2t series c firmware1 CVEscompactlogix 1756-en2t series d1 CVEscompactlogix 1756-en2t series d firmware1 CVEscompactlogix 1756-en2tr series a1 CVEscompactlogix 1756-en2tr series a firmware1 CVEscompactlogix 1756-en2tr series b1 CVEscompactlogix 1756-en2tr series b firmware1 CVEscompactlogix 1756-en3tr series a1 CVEscompactlogix 1756-en3tr series a firmware1 CVEscompactlogix 17681 CVEscompactlogix 1768-l431 CVEscompactlogix 1768-l43 firmware1 CVEscompactlogix 1768-l451 CVEscompactlogix 1768-l45 firmware1 CVEscompactlogix 17691 CVEscompactlogix 1769-l16er-bb1b1 CVEscompactlogix 1769-l16er-bb1b firmware1 CVEscompactlogix 1769-l18er-bb1b1 CVEscompactlogix 1769-l18er-bb1b firmware1 CVEscompactlogix 1769-l18erm-bb1b1 CVEscompactlogix 1769-l18erm-bb1b firmware1 CVEscompactlogix 1769-l23e-qb1b1 CVEscompactlogix 1769-l23e-qb1b firmware1 CVEscompactlogix 1769-l23e-qbfc1b1 CVEscompactlogix 1769-l23e-qbfc1b firmware1 CVEscompactlogix 1769-l24er-qb1b1 CVEscompactlogix 1769-l24er-qb1b firmware1 CVEscompactlogix 1769-l24er-qbfc1b1 CVEscompactlogix 1769-l24er-qbfc1b firmware1 CVEscompactlogix 1769-l27erm-qbfc1b1 CVEscompactlogix 1769-l27erm-qbfc1b firmware1 CVEscompactlogix 1769-l30er1 CVEscompactlogix 1769-l30er-nse1 CVEscompactlogix 1769-l30er-nse firmware1 CVEscompactlogix 1769-l30er firmware1 CVEscompactlogix 1769-l30erm1 CVEscompactlogix 1769-l30erm firmware1 CVEscompactlogix 1769-l311 CVEscompactlogix 1769-l31 firmware1 CVEscompactlogix 1769-l32c1 CVEscompactlogix 1769-l32c firmware1 CVEscompactlogix 1769-l32e1 CVEscompactlogix 1769-l32e firmware1 CVEscompactlogix 1769-l33er1 CVEscompactlogix 1769-l33er firmware1 CVEscompactlogix 1769-l33erm1 CVEscompactlogix 1769-l33erm firmware1 CVEscompactlogix 1769-l35cr1 CVEscompactlogix 1769-l35cr firmware1 CVEscompactlogix 1769-l35e1 CVEscompactlogix 1769-l35e firmware1 CVEscompactlogix 1769-l36erm1 CVEscompactlogix 1769-l36erm firmware1 CVEscompactlogix 5380 process1 CVEscompactlogix 5380 process firmware1 CVEscompactlogix 55801 CVEscompactlogix 5580 firmware1 CVEscompactlogix controllers firmware1 CVEscompactlogix firmware1 CVEsconnected component workbench1 CVEscontrollogix 5550 firmware1 CVEscontrollogix 5560 controller1 CVEscontrollogix 5560 controller firmware1 CVEscontrollogix 5560 firmware1 CVEscontrollogix 5560 redundant controller1 CVEscontrollogix 5560 redundant controller firmware1 CVEscontrollogix 5570 redundancy1 CVEscontrollogix 5570 redundancy firmware1 CVEscontrollogix controllers firmware1 CVEscontrollogix firmware1 CVEscontrollogix l55 controller1 CVEscontrollogix l55 controller firmware1 CVEsdrivelogix 1794-l341 CVEsdrivelogix 55601 CVEsdrivelogix 5730 firmware1 CVEsdrivetools add-on profiles1 CVEsdrivetools sp1 CVEseds hardware installation tool1 CVEsembedded edge compute module1 CVEs

Recent Vulnerabilities

View all 345
CVE-2025-9466HIGH 7.5

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

CVE-2025-9465HIGH 7.5

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

CVE-2025-9464HIGH 7.5

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive.

CVE-2025-9283HIGH 7.5

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

CVE-2025-9282HIGH 7.5

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

CVE-2025-9281HIGH 7.5

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots

CVE-2025-9280HIGH 7.5

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.

CVE-2025-9279HIGH 7.5

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

CVE-2025-9278HIGH 7.5

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible.

CVE-2025-11918HIGH 7.3

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.

CVE-2025-9068HIGH 7.8

A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.

CVE-2025-9067HIGH 7.8

A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.

CVE-2025-9064CRITICAL 9.1

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

CVE-2025-9063CRITICAL 9.8

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic information, event logs, and more.

CVE-2025-7330MEDIUM 6.5

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.

CVE-2025-7329MEDIUM 4.8

A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login.

CVE-2025-7328CRITICAL 9.8

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would no longer be able to communicate through NATR as a result of denial-of-service or NAT rule modifications. NAT rule modification could also result in device communication to incorrect endpoints. Admin account takeover could allow modification of configuration and require physical access to restore.

CVE-2025-9364HIGH 8.8

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.

CVE-2025-9166HIGH 7.5

A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue could result in a major nonrecoverable fault on the controller.

CVE-2025-9161HIGH 8.8

A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.

CVE-2025-9065HIGH 8.8

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.

CVE-2025-8008MEDIUM 6.5

A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash.

CVE-2025-8007MEDIUM 6.5

A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to unexpected system crashes and loss of device availability.

CVE-2025-7970HIGH 7.5

A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise.

CVE-2025-7972CRITICAL 9.1

A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.