CVE-2026-8085
published 2026-07-14CVE-2026-8085: A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from…
PriorityP341high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.18%
7.9th percentile
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rockwell_automation | arena_simulation | — | — |
| rockwellautomation | arena | < 17.00.01 | 17.00.01 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv4.07.0HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Rockwell Automation Arena Simulation Siman model.exe out-of-bounds write (Nessus ID 329331)
vuldb·2026-07-25·CVSS 7.3
CVE-2026-8085 [HIGH] Rockwell Automation Arena Simulation Siman model.exe out-of-bounds write (Nessus ID 329331)
A vulnerability was found in Rockwell Automation Arena Simulation. It has been declared as problematic. Affected is an unknown function of the file model.exe of the component Siman. The manipulation results in out-of-bounds write.
This vulnerability is known as CVE-2026-8085. Attacking locally is a requirement. No exploit is available.
GHSA
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component.
ghsa_unreviewed·2026-07-14
CVE-2026-8085 [HIGH] CWE-787 A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component.
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
No detection rules found.
No public exploits indexed.
2026-07-14
Published