Rockwell Automation, a leading provider of industrial automation solutions, has disclosed multiple critical vulnerabilities in its Arena software that could allow attackers to execute remote code.
The company has released security updates to address these high-severity flaws, urging users to upgrade to the latest version immediately.
Four distinct vulnerabilities have been identified in Arena software versions 16.20.03 and prior:
All four vulnerabilities have been assigned a CVSS v3.1 base score of 7.8 and a CVSS v4.0 base score of 8.5, indicating their high severity.
Rockwell Automation experts discovered that the vulnerabilities can be exploited by crafting malicious DOE files that manipulate memory allocation and resource usage in the Arena software.
While the attack requires a legitimate user to execute the malicious code, the potential impact is significant.
Free Webinar on Best Practices for API vulnerability & Penetration Testing: Free Registration
If successfully exploited, these vulnerabilities could allow an attacker to:-
Rockwell Automation has released version 16.20.06 of the Arena software, which addresses all four vulnerabilities. Users are strongly advised to upgrade to this version or later to mitigate the risk.
Additionally, the company recommends implementing security best practices for industrial automation control systems to minimize vulnerability risks. These may include:-
This disclosure highlights the ongoing cybersecurity challenges faced by the industrial automation sector. As critical infrastructure becomes increasingly connected, the potential impact of such vulnerabilities grows more severe.
Organizations relying on Rockwell Automation’s Arena software should prioritize this update to ensure the security and integrity of their operations.
The vulnerabilities were reported through the Zero Day Initiative (ZDI), underscoring the importance of responsible disclosure and collaboration between security researchers and vendors in identifying and addressing potential threats to industrial systems.
Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses
Four security flaws described in the supplied Apache Struts advisories could expose affected applications to…
A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…
A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…
Every function in a security operations center, from alert triage to incident response, depends on…
ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…
Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…