← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 13, 2026 · 12:00via CISA Alerts

AVEVA Enterprise SCADA

Brief

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCADA =2024

  • =2023
  • =2022
  • =2024
  • =2023
  • =2022
  • "Mode" setting from 'Binary Formatter' to 'Json'. Change "BinarySerializer" - "AcceptBinaryFormattedData" setting from 'true' to 'false'. Re-cache the XOS Event Handlers assembly

Mitigation

Client Components: Configure clients/products that interface with Enterprise SCADA to only use JSON serialization.

Read more on CISA Alerts