HIGH
Rockwell Automation Arena® - Memory Corruption Vulnerability
Published Jul 14, 2026
7.0
HIGHCVSS 4.0
EPSS 0.27%
Description
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Affected products
-
- Version V17.00.00 and priorStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Rockwell Automation | Arena® Simulation | unaffected |
|
- < 17.00.01
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to V17.00.01 or later
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43668 Advisory
- https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1784.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43668 | Advisory | |
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1784.html | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Rockwell
Published Jul 14, 2026
Updated Jul 14, 2026
Reserved May 7, 2026
Link CVE-2026-8085
CISA Vulnrichment
Updated Jul 14, 2026
ENISA EUVD
EUVD-2026-43668 Assigner Rockwell
Published Jul 14, 2026
Updated Jul 14, 2026
Exploited since n/a
Link EUVD-2026-43668