Security1 distinct publisher2 min readPublished
CISA's advisory covers Series B 5.202 and Series C 7.101 across five critical infrastructure sectors, but the published text carries no CVSS vectors and no corrected version numbers for an asset owner to upgrade to.
The Watch · Security desk

security
Mitsubishi's CNC advisory now lists 18 models exposed on TCP port 6831 distinct publisher
security
ASE2000's IEC 104 client accepts a forged peer certificate through version 2.371 distinct publisher
security
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions1 distinct publisher
security
Siemens IoT2050 gateways ship a Node-RED interface that asks nobody for a password1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
Both issues live on the same web interface and behind the same login. The out-of-bounds write is described as reachable by an attacker with low-level authentication, and the advisory says that path leads to remote code execution on the device [2]. The crash needs an authenticated, network-adjacent attacker sending crafted requests to that interface [3]. At each site, the useful question is who already holds a Historian ME credential and where that credential is written down, not how severe the flaw sounds on paper.
The Metrics sections arrive empty in the published text, so there is no CVSS vector or base score to sort on [7]. That does not hold up triage. An out-of-bounds write on an embedded web service with a low authentication bar is a workable exploitation target [2], and the crash bug carries the same precondition, so it changes nothing in the priority order [3]. The write is where the priority attention belongs.
The fix is the part that will stall teams. Rockwell's remediation text addresses customers who are not able to upgrade to one of the corrected versions and points them at the vendor's security best practices document, with TechConnect and PSIRT for questions [5]. The corrected version numbers do not appear in the advisory text [6]. Two CVE IDs against two affected series produces four product-and-identifier combinations to match in an asset inventory, and all four are missing a target version [11]. The advisory also lists both IDs against both series without saying which ID is the write and which is the crash [10], so a tracker keyed on CVE cannot tell an operator whether a given row is a data gap or a shell.
CISA's guidance in the advisory is the standard set: keep control system devices off the internet, put them behind firewalls and away from business networks, and use VPNs for remote access while treating the VPN as only as secure as the devices attached to it [9]. Boilerplate, and with no version to move to, it is the operative instruction.
Rockwell reported both flaws to CISA itself, and the advisory makes no claim of exploitation [8]. This reads as a vendor disclosure, with nothing in the record pointing to a live campaign. What earns it a ticket is placement. A machine-edition historian exists to collect process data and hand it to people who are not on the process network, which is precisely where a low-privilege account tends to exist already. Five critical infrastructure sectors are named in the background section [12]. Until a corrected version is published, exposure shrinks only through enumeration of every account that can authenticate to the device.
Ranked by verification strength, evidence, and original report placement.
CISA's ICS advisory for Rockwell Automation Historian ME lists Series B 5.202 and Series C 7.101 as affected, each against CVE-2025-12768 and CVE-2026-12661.
The advisory states that a security issue in FactoryTalk Historian Machine Edition lets an attacker with low-level authentication achieve remote code execution on the affected device, with relevant weakness CWE-787 Out-of-bounds Write.
A second issue is a denial of service: a network adjacent attacker who is authenticated can send crafted requests to the web interface, causing buffer overflow conditions that may crash the device and make it unresponsive. Relevant weakness is CWE-121 Stack-based Buffer Overflow.
The advisory lists the affected product's critical infrastructure sectors as Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, and Water and Wastewater Systems, with countries/areas deployed listed as worldwide and company headquarters in the United States.
Remediation guidance says customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices, and directs questions to TechConnect and to Rockwell PSIRT at [email protected].
The advisory text refers to 'corrected versions' but does not state any corrected version numbers for Series B or Series C.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Authoritative but self-truncating
Provenance is as good as it gets — the facts come from the body that issues the advisory, so there is nothing to corroborate. The weakness is internal: the Metrics blocks under both vulnerability entries are empty, and the phrase "corrected versions" appears with no version numbers behind it. The two details an asset owner needs most are missing from the one document that would carry them.
No install or patch data
"Worldwide" and five named sectors describe where Historian ME might be found, not how much of it is out there, how much sits on 5.202 or 7.101, or whether a single site has remediated. With no fixed version published, patch uptake is not merely unmeasured — it is not yet measurable.
Drier than the situation warrants
Nothing here is inflated; if anything the register is too flat. "Remote code execution" on historians sitting in water treatment and healthcare environments is delivered in the same tone as the contact-us links, and the genuinely awkward fact — that the fix you are told to install has no version number — is buried in boilerplate rather than flagged. Our own framing leans on the low-privilege-to-code-execution path, which is exactly what CISA describes.
Vendor-reported, vendor-scoped
Rockwell brought these bugs to CISA itself, which is the good version of this story — but it also means the vendor set the level of detail, and what got left out follows a familiar pattern: no scores, no component, no fix version, and a support-ticket path as the route to the rest. CISA's own incentive pulls the other way, toward publishing broad defensive guidance early, which is why the segmentation advice is fuller than the product specifics.
Solid on what happened, blind on how bad
Take the affected versions, the two weakness classes and the authenticated precondition as settled — a primary issuer stated them and no one disputes them. Severity, urgency and the upgrade path are a different matter, and no amount of re-reading this advisory resolves them, since the mapping between the two identifiers and the two defects is never made.