Back

HIGH

Rockwell Automation Arena® - Memory Corruption Vulnerability

Published Jul 14, 2026

Description

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.

Affected products

Remediation

Vendor solution

Upgrade to  V17.00.01 or later

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Rockwell
Published Jul 14, 2026
Updated Jul 14, 2026
Reserved May 7, 2026
CISA Vulnrichment
Updated Jul 14, 2026
NVD
Status Analyzed
Modified Jul 15, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Rockwell
Published Jul 14, 2026
Updated Jul 14, 2026
Exploited since n/a
EUVD-2026-43668