Rockwell Automation has released patches for four high-severity vulnerabilities in its Arena Simulation software that could allow an attacker to execute arbitrary code on an affected system, according to advisories from CISA and Rockwell.
Arena Simulation is discrete-event simulation software used to model, visualize, and test operational workflows before changes are implemented in live production environments. The tool is widely deployed across manufacturing, supply chain, healthcare, and defense sectors, according to Rockwell’s own customer materials.
Details of the Flaws
The vulnerabilities, tracked as CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314, are memory corruption issues caused by improper validation of user-supplied data, resulting in out-of-bounds write conditions. Successful exploitation could let an attacker execute arbitrary code within the context of the Arena process.
Arena versions up to and including 17.00.00 are affected. Rockwell has resolved the issues in version 17.00.01, and organizations running older builds are advised to update.
User Interaction Required
The flaws cannot be exploited remotely without user interaction. An attacker would need to trick a target into opening a malicious Arena experiment or model file. Michael Heinzl, the researcher who discovered the vulnerabilities, told SecurityWeek that these file types are opened routinely as part of normal workflows, meaning a booby-trapped file might not raise suspicion in a targeted social engineering attempt.
Heinzl noted that code execution from these bugs would be confined to the same privileges as the Arena process itself, and that any further pivot to more sensitive systems would depend on how an organization has segmented Arena within its network.
Broader Scope of Findings
According to Heinzl, he actually identified 17 distinct vulnerabilities in Arena, but Rockwell chose to group related issues by affected component, resulting in only four CVEs being assigned. The researcher has published all 17 advisories on his personal website.
Both CISA and Rockwell state there is no evidence of in-the-wild exploitation of these vulnerabilities at this time. Organizations using Arena Simulation are encouraged to update to version 17.00.01 and exercise caution when opening experiment or model files from untrusted sources.
