CVE-2025-11862: Rockwell Automation Verve Asset Manager

High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API.

Affected products

Published 2025-11-11. Last modified 2026-06-17.