CVE-2025-9065: Rockwellautomation Thinmanager

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.

Affected products

Published 2025-09-09. Last modified 2026-06-17.