← Back
VulnerabilityCISA Advisories·9 hours ago

Rockwell Automation Historian ME

CISA has disclosed two vulnerabilities in Rockwell Automation Historian ME Series B 5.202 and Series C 7.101, with CVE-2025-12768 allowing remote code execution via out-of-bounds write (CVSS 8.0) and CVE-2026-12661 enabling denial-of-service through stack-based buffer overflow (CVSS 4.5). The vulnerabilities affect critical infrastructure sectors including chemical, manufacturing, food and agriculture, and water systems, with exploitation requiring low-level or authenticated network-adjacent access respectively. CISA recommends minimizing network exposure, implementing network segmentation, and applying Rockwell Automation's security best practices until patches become available.

Read full article at CISA Advisories

Related Articles

VulnerabilityThe Hacker News·3 hours ago

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an authentication weakness that, under default

VulnerabilityHelp Net Security·5 hours ago

CISA review makes the case for eliminating vulnerability classes

CISA argues that the security industry's traditional approach of treating vulnerabilities as individual fixes is ineffective against attackers, and advocates instead for eliminating entire vulnerability classes at their root during software development. Rather than pursuing endless patching cycles, the agency contends that developers can prevent the weaknesses most likely to be exploited by threat actors by addressing fundamental causes in the development process.

VulnerabilityCybersecurity Dive·6 hours ago

Frontier AI used to help exploit flaws in key industrial devices

Frontier artificial intelligence models like Claude are now being leveraged to identify and exploit vulnerabilities in programmable logic controllers (PLCs) that control critical infrastructure such as water utilities. This development demonstrates how advanced AI systems can be weaponized to streamline the reconnaissance and attack planning phases against operational technology environments.

VulnerabilitySecurity Affairs·6 hours ago

Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague

Security researcher Chaotic Eclipse has released PrettyPrague, a proof-of-concept exploit for a previously unknown privilege escalation vulnerability in GenDigital Avast Antivirus. The zero-day flaw allows attackers to elevate privileges on affected systems running the antivirus software.