The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations to immediately address a newly disclosed high-severity vulnerability affecting Rockwell Automation ThinManager, software commonly used in industrial control systems across critical infrastructure sectors. The advisory, released July 23, identifies a path traversal vulnerability tracked as CVE-2026-11917 that could allow an authenticated attacker to write arbitrary files outside permitted directories. CISA assigned the flaw a CVSS v3.1 score of 8.1, rating it High severity. The affected software is deployed worldwide in industries including energy, water and wastewater, food and agriculture, chemical manufacturing, and critical manufacturing.
Affected Versions and Available Updates
According to CISA, the vulnerability affects several supported versions of ThinManager. Organizations running versions 13.0.0 through 13.0.7 should update to 13.0.8, while those using 13.1.x, 13.2.x, and 14.0.x should upgrade to 13.1.6, 13.2.5, and 14.0.3, respectively. Rockwell Automation reported the issue to CISA and has released patched versions to address the vulnerability. Organizations that cannot update immediately should follow the vendor’s published security recommendations until patches can be applied.
CISA Recommends Immediate Mitigation
In addition to installing the latest software updates, CISA recommends minimizing network exposure for industrial control systems by ensuring they are not directly accessible from the public internet. The agency also advises placing operational technology networks behind firewalls, separating them from business networks whenever possible, and using fully updated VPNs for remote access. Before deploying any defensive measures, organizations should conduct a risk assessment to determine the potential operational impact. CISA says no known public exploitation of this specific vulnerability has been reported at this time, but organizations should review the official advisory and Rockwell Automation’s security guidance to determine how the issue may affect their environments.
What to Read Next
CMS Issues Technical Correction to 2027 Affordable Care Act Benefit and Payment Parameters Rule