Rockwell Automation has patched four high-severity vulnerabilities in Arena Simulation that could allow arbitrary code execution if a user opens a malicious file. The flaws affect Arena versions up to 17.00.00 and are tracked as CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314. #RockwellAutomation #ArenaSimulation #CVE-2026-8085 #CVE-2026-8312 #CVE-2026-8313 #CVE-2026-8314
Keypoints
- Rockwell patched four high-severity flaws in Arena Simulation.
- The vulnerabilities could enable arbitrary code execution on affected systems.
- The issues stem from improper validation of user-supplied data and out-of-bounds writes.
- Arena versions up to and including 17.00.00 are affected, and 17.00.01 fixes them.
- Exploitation requires user interaction and no in-the-wild abuse has been observed.
Read More: https://www.securityweek.com/rockwell-patches-code-execution-flaws-in-arena-simulation-software/