CVE-2025-9065: Rockwellautomation Thinmanager
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.
Affected products
- Rockwellautomation Thinmanager: from 13.0.0, up to and including 14.0.0
Published 2025-09-09. Last modified 2026-06-17.