<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:rockwell_automation:historian_me:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3arockwell_automationhistorian_me/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 17:10:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3arockwell_automationhistorian_me/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Rockwell Automation Historian ME</title><link>https://feed.craftedsignal.io/briefs/2026-09-rockwell-historian/</link><pubDate>Tue, 01 Sep 2026 17:10:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-rockwell-historian/</guid><description>Rockwell Automation Historian ME series B and C contain multiple vulnerabilities, including an out-of-bounds write allowing remote code execution and a buffer overflow causing denial-of-service.</description><content:encoded><![CDATA[<p>Rockwell Automation has disclosed two vulnerabilities affecting FactoryTalk Historian Machine Edition (ME) versions Series B 5.202 and Series C 7.101. These vulnerabilities, tracked as CVE-2025-12768 and CVE-2026-12661, expose critical infrastructure to severe operational risks. CVE-2025-12768 is an out-of-bounds write vulnerability (CWE-787) that allows an authenticated attacker with low-level access to achieve remote code execution. CVE-2026-12661 is a stack-based buffer overflow (CWE-121) triggered by crafted requests sent to the web interface, which can lead to a device crash and denial-of-service conditions. These vulnerabilities impact diverse sectors, including water, healthcare, food production, and manufacturing. Given the critical nature of these industrial control systems, defenders must prioritize network isolation and ensure administrative access controls are rigorously enforced to prevent unauthorized exploitation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could result in full system compromise via remote code execution (CVE-2025-12768) or the loss of availability through forced device crashes (CVE-2026-12661). These systems are deployed in vital critical infrastructure sectors, including chemical processing, healthcare, and water systems. If compromised, attackers could potentially manipulate industrial processes or render safety-critical monitoring systems unresponsive. No known public exploitation has been reported as of September 2026.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the following actions to secure affected Rockwell Automation Historian ME environments:</p>
<ul>
<li>Immediately isolate all affected Historian ME controllers behind firewalls and restrict access to the web interface to authorized management subnets only.</li>
<li>Contact Rockwell Automation TechConnect for guidance on obtaining and deploying the latest firmware or software patches for Series B 5.202 and Series C 7.101.</li>
<li>Monitor network traffic to the device web interface for anomalous, malformed, or excessively large HTTP requests that may indicate exploitation attempts for CVE-2026-12661.</li>
<li>Review all existing authenticated user accounts on the affected Historian ME devices to identify and disable unauthorized or dormant low-level accounts that could be leveraged for CVE-2025-12768.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>