Rockwell Automation has released corrected versions. Customers unable to upgrade should follow security best practices at the Rockwell Automation support portal. CISA recommends minimizing network exposure, locating control system networks behind firewalls, isolating them from business networks, and using VPNs for remote access.
Quick answers
What is CVE-2026-12661?
Rockwell Automation has released corrected versions. Customers unable to upgrade should follow security best practices at the Rockwell Automation support portal. CISA recommends minimizing network exposure, locating control system networks behind firewalls, isolating them from business networks, and using VPNs for remote access.
How severe is CVE-2026-12661?
high, CVSS 8
Is CVE-2026-12661 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-12661 be mitigated?
Rockwell Automation has released corrected versions. Customers unable to upgrade should follow security best practices at the Rockwell Automation support portal. CISA recommends minimizing network exposure, locating control system networks behind firewalls, isolating them from business networks, and using VPNs for remote access.
CVSS
8
Vendor
Rockwell Automation
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Rockwell Automation Historian ME Series B 5.202, Rockwell Automation Historian ME Series C 7.101
Mitigation
Rockwell Automation has released corrected versions. Customers unable to upgrade should follow security best practices at the Rockwell Automation support portal. CISA recommends minimizing network exposure, locating control system networks behind firewalls, isolating them from business networks, and using VPNs for remote access.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an industrial control systems advisory (ICSA-26-244-06) disclosing multiple vulnerabilities in Rockwell Automation FactoryTalk Historian Machine Edition. CVE-2025-12768 is an out-of-bounds write flaw that could allow remote code execution for an attacker with low-level authentication. CVE-2026-12661 is a denial-of-service vulnerability that could cause device crashes via crafted web interface requests from a network-adjacent, authenticated attacker. Affected products include Series B version 5.202 and Series C version 7.101 of Rockwell Automation Historian ME. The vulnerabilities span critical infrastructure sectors worldwide, including chemical, manufacturing, food and agriculture, healthcare, and water and wastewater systems.