Cyber Resilience
← All news
Confirmed

AVEVA Enterprise SCADA

Our takeCISA reports active exploitation of CVE-2025-7639 in AVEVA Enterprise SCADA that lets attackers tamper with serialized data and achieve code execution on deserialization. Patch immediately if you run this OT system (many small water, manufacturing, and industrial sites do); larger enterprises should treat it as urgent too.
Sources (1)
What this means for you — Security leader:Patch AVEVA Enterprise SCADA 2025, 2024, and 2023 versions immediately; CISA reports active exploitation of CVE-2025-7639 allowing remote code execution via deserialization.
What this means for you — Lean IT orgs:If you run AVEVA Enterprise SCADA on any version from 2023-2025, update it right away. Most lean teams without industrial systems can ignore this.
What this means for you — MSP:Check client environments for AVEVA Enterprise SCADA 2023-2025 deployments and patch CVE-2025-7639 immediately; CISA reports in-the-wild exploitation.
What this means for you — Researcher:CISA advisory ICSA-26-225-01 details CVE-2025-7639 in AVEVA Enterprise SCADA (2023-2025); successful exploitation allows tampering with serialized objects leading to RCE on deserialization.