Patch released Arena Simulation ics-ot-iot Rockwell Automation
Rockwell Patches Code Execution Flaws in Arena Simulation Software
CVE Tools coverage
Rockwell Automation has issued updates addressing four critical code execution vulnerabilities in its Arena Simulation software, as reported by CISA and Rockwell in recent advisories. The affected versions include all releases up to 17.00.00, with the fix available in version 17.00.01. The flaws—CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314—are memory corruption issues caused by insufficient validation of user input, potentially enabling attackers to run arbitrary code if a user opens a malicious file. While remote exploitation is not possible without user interaction, the widespread use of Arena in industries like healthcare, logistics, and defense makes these vulnerabilities particularly concerning.