Rockwell Historian ME flaws risk RCE, crash
CISA advises two vulnerabilities in Rockwell Automation Historian ME could let attackers achieve remote code execution or crash the device.
CISA published an ICS advisory for Rockwell Automation's FactoryTalk Historian Machine Edition (Historian ME), affecting Series B version 5.202 and Series C version 7.101. Two vulnerabilities were disclosed: CVE-2025-12768, an out-of-bounds write (CWE-787) that could allow a low-privilege authenticated attacker to achieve remote code execution on the device; and CVE-2026-12661, a stack-based buffer overflow (CWE-121) reachable via the web interface by a network-adjacent authenticated attacker, resulting in a denial-of-service crash.
Historian ME is used in industrial environments across chemical, critical manufacturing, food and agriculture, healthcare, and water/wastewater sectors worldwide. Rockwell reported these issues to CISA itself, and there is no known public exploitation at this time. CISA and Rockwell recommend upgrading to corrected versions where possible, applying Rockwell's security best practices for customers unable to upgrade, minimizing network exposure of control system devices, isolating ICS networks behind firewalls, and using secure remote access methods such as VPNs. Standard ICS defense-in-depth and anti-phishing guidance is also reiterated.
Given the RCE potential and crash/DoS impact on industrial historian software deployed across multiple critical infrastructure sectors, this warrants prompt patching attention by affected asset owners, though the lack of known exploitation and requirement for authentication moderate the immediate urgency.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free