Threat+Constellation
Live UTC
← Incidents
INCIDENT 117PhishingLOW / UNDER REVIEWSourced

AVEVA Enterprise SCADA

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization.</strong></p> <p>The following versions of AVEVA Enterprise SCADA are affected:</p> <ul> <li>Enterprise SCADA 2025 (CVE-2025-7639)</li> <li>Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639)</li> <li>Enterprise SCADA >=2023|<=2023_SP1 (CVE-2025-7639)</li> <li>Ente…

Last evidence update
13 AUG 2026 · 12:00 UTC
Source count
1
Status
reported
United StatesUnited KingdomManufacturingEnergyDefenseCVE-2025-7639
Preceded by

Weak signals the observatory recorded before this incident became visible.

Observation history

How this record has evolved as evidence accumulated.

18 AUG · 18:23 UTC
Initial report
Evidence