PT-2026-60348 · Rockwell Automation · Arena

CVE-2026-6071

·

Published

2026-07-15

·

Updated

2026-09-03

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Rockwell Automation Arena Simulation (affected versions not specified)
Description A remote code execution issue occurs during the parsing of DOE files. This flaw allows a remote attacker to perform an out-of-bounds write, which involves writing data past the end of an allocated object, potentially enabling the execution of arbitrary code within the context of the current process. Exploitation requires a legitimate user to open a malicious file or visit a malicious page.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6071
ZDI-26-438

Affected Products

Arena