← All Advisories

CVE-2026-8312

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-8312

Key Details

CVECVE-2026-8312
CVSS Score / Version7.3 (High) / CVSS v3.1
Updated2026-07-15
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRockwell Automation arena and Rockwell Auotmation Arena® Simulation
Classified asCWE-787 (Out-of-bounds Write)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Rockwell Automationarena
Rockwell AuotmationArena® Simulation
SubsystemsGeneral OT
SectorsMultiple

What to Know

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. (NVD)

What to Do

Monitor Rockwell Automation's and Rockwell Auotmation's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-8312
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-8312
Vendor advisoryhttps://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1784.html