CVE-2025-11696: Rockwell Automation Studio 5000 Simulation Interface

High severity, CVSS 8.9. EPSS: 0.2% chance of exploitation in the next 30 days.

A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes.

Affected products

Published 2025-11-11. Last modified 2026-06-17.