← All Advisories

CVE-2026-6071

Last refreshed2026-10-07

Status: UPDATED  |  Advisory ID: CVE-2026-6071

Key Details

CVECVE-2026-6071
CVSS Score / Version7.5 (High) / CVSS v4.0
Updated2026-09-03
Affected productsRockwell Automation arena
Classified asCWE-787 (Out-of-bounds Write)
Exploitation prediction (EPSS)0.51% probability of exploitation in the next 30 days (42% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Rockwell Automationarena
SubsystemsGeneral OT
SectorsMultiple

What to Know

A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file. (NVD)

What to Do

Monitor Rockwell Automation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-6071
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-6071