ZeroHour

Vulnerabilities

306 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-9128
+2 in the same advisory: …9127 …9108
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration.

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.

NVD description · AI analysis pending
7.3
group max
<1%
  • rockwellautomation studio 5000 logix designer
CVE-2026-8085
+3 in the same advisory: …8313 …8312 …8314
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component.

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.

NVD description · AI analysis pending
7.0<1%
  • rockwellautomation arena
CVE-2025-9466
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition.

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

NVD description · AI analysis pending
8.7<1%
  • rockwellautomation armorstart lt firmware
CVE-2025-11918
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability.

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.

NVD description · AI analysis pending
7.1<1%
  • rockwellautomation arena
CVE-2025-9067
+1 in the same advisory: …9068
A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx.

A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.

NVD description · AI analysis pending
8.5<1%
  • rockwellautomation factorytalk linx
CVE-2025-9064
+1 in the same advisory: …9063
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete a

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

NVD description · AI analysis pending
8.7
group max
<1%
  • rockwellautomation factorytalk view
CVE-2025-7328
+2 in the same advisory: …7329 …7330
Multiple Broken Authentication security issues exist in the affected product.

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would no longer be able to communicate through NATR as a result of denial-of-service or NAT rule modifications. NAT rule modification could also result in device communication to incorrect endpoints. Admin account takeover could allow modification of configuration and require physical access to restore.

NVD description · AI analysis pending
9.9
group max
<1%
  • rockwellautomation 1783-natr firmware
CVE-2025-9364
An open database issue exists in the affected product and version.

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.

NVD description · AI analysis pending
8.7<1%
  • rockwellautomation factorytalk analytics logixai
CVE-2025-9166
A denial-of-service security issue exists in the affected product and version.

A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue could result in a major nonrecoverable fault on the controller.

NVD description · AI analysis pending
8.2<1%
  • rockwellautomation controllogix 5580 firmware
CVE-2025-9161
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization.

A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.

NVD description · AI analysis pending
7.3<1%
  • rockwellautomation factorytalk optix
CVE-2025-9065
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization.

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.

NVD description · AI analysis pending
8.6<1%
  • rockwellautomation thinmanager
CVE-2025-8008
+1 in the same advisory: …8007
A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the devic

A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash.

NVD description · AI analysis pending
7.1<1%
  • rockwellautomation 1756-en2tr series a firmware
  • rockwellautomation 1756-en2tr series b firmware
  • rockwellautomation 1756-en2tr series c firmware
  • +1 more
CVE-2025-7970
A security issue exists within FactoryTalk Activation Manager.

A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise.

NVD description · AI analysis pending
8.7<1%
  • rockwellautomation factorytalk activation manager
CVE-2025-7972
A security issue exists within the FactoryTalk Linx Network Browser.

A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.

NVD description · AI analysis pending
8.4<1%
  • rockwellautomation factorytalk linx
CVE-2025-7032
+2 in the same advisory: …7033 …7025
A memory abuse issue exists in the Rockwell Automation Arena® Simulation.

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute code or disclose information.

NVD description · AI analysis pending
8.4<1%
  • rockwellautomation arena
CVE-2025-6377
+1 in the same advisory: …6376
A remote code execution security issue exists in the Rockwell Automation Arena®.

A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, a threat actor could execute arbitrary code on the target system. The software must run under the context of the administrator in order to cause worse case impact. This is reflected in the Rockwell CVSS score, as AT:P.

NVD description · AI analysis pending
7.1<1%
  • rockwellautomation arena
CVE-2025-3618
+1 in the same advisory: …3617
A denial-of-service vulnerability exists in the Rockwell Automation ThinManager.

A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on the target software.

NVD description · AI analysis pending
8.52%
  • rockwellautomation thinmanager
CVE-2025-3289
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow.

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

NVD description · AI analysis pending
8.5<1%
  • rockwellautomation arena