Junglewise Threat Intelligence

CVE-2026-8085: Rockwell Automation Arena Simulation out-of-bounds write in model.exe

CVE-2026-8085 · Severity: info · CVSS 7.8 · Published 2026-07-14

Technologies: Rockwell Automation Arena Simulation. Vendors: Rockwell Automation.

Executive brief

Rockwell Automation Arena Simulation is a software tool used by businesses to model and optimize complex industrial systems. A security flaw in its modeling component allows an attacker to take control of a user's computer if the user is tricked into opening a specially crafted, malicious simulation file. This could lead to the theft of sensitive data, disruption of operations, or further infection of the corporate network.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the model.exe (Siman) component of Rockwell Automation Arena Simulation. The issue is caused by improper validation of user-supplied data within simulation files. An attacker can exploit this by convincing a user to open a specially crafted file, leading to memory corruption and the execution of arbitrary code in the context of the current process. The vulnerability is addressed in version V17.00.01.

Affected products

  • Rockwell Automation Arena Simulation V17.00.00 and prior

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched: Fixed in version V17.00.01

References

Related threats