← Back to Feed

Rockwell Automation Historian ME

CVE-2025-12768CVE-2026-12661

September 1, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-12768 A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieveremote code execution on the affected device. View CVE Details Affected Products Rockwell Automation Historian ME Vendor:Rockwell Automation Product Version:Rockwell Automation Series B: 5.202, Rockwell Automation Series C: 7.101 Product Status:known_affected Remediations MitigationCustomers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automations security best practices found at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight MitigationIf you have any questions regarding the security issue(s) above and how to mitigate them, contact TechConnect for help. More information can be found at https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html.https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html MitigationIf you have any questions regarding this disclosure, please contact PSIRT Email:...

Key Takeaways

  • CISA published an advisory for Rockwell Automation Historian ME covering vulnerabilities that could crash the device being accessed, with an out-of-bounds write allowing remote code execution.
  • Affected versions include Historian ME Series B 5.202, tied to CVE-2025-12768 and CVE-2026-12661, so operators should verify their deployments against the advisory.
  • Organizations using Historian ME should apply Rockwell's patched versions promptly because the out-of-bounds write flaw can lead to full remote code execution.
☕ Buy a Coffee