CVE-2026-8312
HIGHRockwell Automation Arena® - Memory Corruption Vulnerability
Title source: cnaDescription
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
References (1)
Core 1
Scores
CVSS v3
7.3
EPSS
0.0018
EPSS Percentile
7.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (2)
Rockwell Auotmation/Arena® Simulation
V17.00.00 and prior
rockwellautomation/arena
< 17.00.01
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026