CVE-2026-6071: Rockwell Automation Arena
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.
Affected products
- Rockwell Automation Arena: up to and including 16.20.08
Published 2026-09-03. Last modified 2026-09-03.