www.cisa.gov 8/13/2026, 5:51:28 PM · external

High risk AVEVA SCADA bug allows remote code execution

CyberSIXT Evidence Panel
Primary Source aveva.com

THE ICS Advisory ICSA-26-225-01 addresses a critical vulnerability in AVEVA Enterprise SCADA that could allow attackers to tamper with serialized data, potentially resulting in code execution during deserialization. Affected versions include several releases from 2021 to 2025. The CVSS score for the vulnerability is 7.1, indicating a high severity.

Mitigation recommendations include upgrading to fixed versions, changing configuration settings to use JSON instead of binary serialization, and auditing permissions related to 'DNA Authority - Operator' rights. CISA emphasizes the importance of performing risk assessments and implementing cybersecurity best practices to protect against exploitation.

View Primary Source Via www.cisa.gov

Article by CyberSIXT