← Back to home
ICSA-26-204-05  ·  Published 2026-07-23  ·  View on CISA ICS-CERT ↗

Rockwell Automation ThinManager

CVSS 8.1 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.

CVEs (1)

Remediations

  • Users using the affected software, should upgrade to one of the corrected versions as follows:
  • ThinManager Versions 13.0.0 - 13.0.7 --> 13.0.8
  • ThinManager Versions 13.1.0 - 13.1.5 --> 13.1.6
  • ThinManager Versions 13.2.0 - 13.2.4 --> 13.2.5
  • ThinManager Versions 14.0.0 - 14.0.2 --> 14.0.3
  • Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices.
  • For more information, refer to Rockwell Automation's Securitry Advisory page.

Affected Vendors

Rockwell Automation

Affected Products (4)

Rockwell Automation · ThinManager >=13.0.0|<13.0.7
Rockwell Automation · ThinManager >=13.1.0|<13.1.5
Rockwell Automation · ThinManager >=13.2.0|<13.2.4
Rockwell Automation · ThinManager >=14.0.0|<14.0.2

Affected Sectors

Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more