{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/historian-me-series-c-7.101/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rockwell_automation:historian_me:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2025-12768"},{"id":"CVE-2026-12661"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Historian ME (Series B 5.202)","Historian ME (Series C 7.101)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Rockwell Automation"],"content_html":"\u003cp\u003eRockwell Automation has disclosed two vulnerabilities affecting FactoryTalk Historian Machine Edition (ME) versions Series B 5.202 and Series C 7.101. These vulnerabilities, tracked as CVE-2025-12768 and CVE-2026-12661, expose critical infrastructure to severe operational risks. CVE-2025-12768 is an out-of-bounds write vulnerability (CWE-787) that allows an authenticated attacker with low-level access to achieve remote code execution. CVE-2026-12661 is a stack-based buffer overflow (CWE-121) triggered by crafted requests sent to the web interface, which can lead to a device crash and denial-of-service conditions. These vulnerabilities impact diverse sectors, including water, healthcare, food production, and manufacturing. Given the critical nature of these industrial control systems, defenders must prioritize network isolation and ensure administrative access controls are rigorously enforced to prevent unauthorized exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in full system compromise via remote code execution (CVE-2025-12768) or the loss of availability through forced device crashes (CVE-2026-12661). These systems are deployed in vital critical infrastructure sectors, including chemical processing, healthcare, and water systems. If compromised, attackers could potentially manipulate industrial processes or render safety-critical monitoring systems unresponsive. No known public exploitation has been reported as of September 2026.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to secure affected Rockwell Automation Historian ME environments:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate all affected Historian ME controllers behind firewalls and restrict access to the web interface to authorized management subnets only.\u003c/li\u003e\n\u003cli\u003eContact Rockwell Automation TechConnect for guidance on obtaining and deploying the latest firmware or software patches for Series B 5.202 and Series C 7.101.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic to the device web interface for anomalous, malformed, or excessively large HTTP requests that may indicate exploitation attempts for CVE-2026-12661.\u003c/li\u003e\n\u003cli\u003eReview all existing authenticated user accounts on the affected Historian ME devices to identify and disable unauthorized or dormant low-level accounts that could be leveraged for CVE-2025-12768.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T17:10:53Z","date_published":"2026-09-01T17:10:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rockwell-historian/","summary":"Rockwell Automation Historian ME series B and C contain multiple vulnerabilities, including an out-of-bounds write allowing remote code execution and a buffer overflow causing denial-of-service.","title":"Critical Vulnerabilities in Rockwell Automation Historian ME","url":"https://feed.craftedsignal.io/briefs/2026-09-rockwell-historian/"}],"language":"en","title":"CraftedSignal Threat Feed - Historian ME (Series C 7.101)","version":"https://jsonfeed.org/version/1.1"}