Cyber Resilience
← All news
Confirmed

AVEVA Enterprise SCADA

Our takeCISA flags a deserialization flaw in AVEVA Enterprise SCADA (CVE-2025-7639, versions 2023 through 2025): tampered serialized data can lead to code execution. If you run this — and plenty of small water and manufacturing operators do — schedule the update in your next OT window.
Sources (1)
What this means for you — Security leader:Update AVEVA Enterprise SCADA to a fixed version immediately if you self-host it (some enterprises). Most lean-IT teams and MSPs use vendor-hosted SCADA and can ignore this.
What this means for you — Lean IT orgs:If you run AVEVA Enterprise SCADA on your own servers, update it now. Most small teams use cloud-hosted SCADA from a vendor and can ignore this.
What this means for you — MSP:Check every client running on-prem AVEVA Enterprise SCADA 2023–2025 and patch CVE-2025-7639 immediately; hosted SCADA instances are unaffected.
What this means for you — Researcher:CISA reports active exploitation of CVE-2025-7639 in AVEVA Enterprise SCADA (2023–2025). Successful exploitation allows tampering with serialized objects that can lead to remote code execution on deserialization.