www.securityweek.com 7/25/2026, 8:40:28 AM · external

Arena Simulation bugs allow arbitrary code execution, now patched

Arena Simulation bugs allow arbitrary code execution, now patched
CyberSIXT Evidence Panel

ROCKWELL Automation has addressed four high-severity vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in its Arena Simulation software, which can lead to arbitrary code execution on affected systems. These vulnerabilities arise from memory corruption linked to improper validation of user data, making exploitation possible if a user opens a malicious file. Versions up to 17.00.00 are impacted, with patches available in version 17.00.01.

The vulnerabilities require user interaction to exploit and do not currently show evidence of in-the-wild exploitation. Research indicates that, although Arena is not a live control system, the software's significant use in various industries underscores the importance of addressing these security flaws.

View Primary Source Via www.securityweek.com

Article by CyberSIXT