AVEVA warns of code-execution flaw in Enterprise SCADA software used across pipelines and manufacturing

A high-severity deserialization bug lets an authenticated operator run code inside the industrial control system. AVEVA has shipped patches for every supported release.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
An industrial control room with SCADA system displays showing pipeline and manufacturing equipment monitoring, a security alert panel highlighting a code execut
Share

Key points

  • AVEVA disclosed CVE-2025-7639, a high-severity flaw in its Enterprise SCADA software, on 13 August 2026 through a CISA advisory.
  • The bug carries a CVSS v3.1 score of 7.1 and could let an authenticated operator run code inside the control system.
  • Every supported release from 2021 through 2025, plus the HMI client, is affected; AVEVA has issued fixed builds for all of them.
  • No public exploitation has been reported, and the vulnerability has high attack complexity.
  • Fully closing the hole requires both installing the patch and switching a serialization setting from Binary Formatter to JSON.

AVEVA, the British industrial software vendor owned by Schneider Electric, has told customers to patch its Enterprise SCADA product after finding a flaw that could let an insider run their own code on the systems that monitor pipelines and factory floors. Schneider Electric's own SCADA tool had a similar code-execution problem we reported on 30 July, which suggests the parent company is running a broader audit of its portfolio.

SCADA, short for Supervisory Control and Data Acquisition, is the software operators use to watch and steer physical equipment: valves on a gas line, motors in a plant, pumps at a water facility. AVEVA's Enterprise SCADA is widely deployed in the oil and gas midstream sector and in critical manufacturing worldwide.

The bug is tracked as CVE-2025-7639 and was published in a CISA advisory on 13 August 2026 alongside AVEVA's own security bulletin AVEVA-2026-005.

What is actually broken?

The software mishandles serialized data, which is data packaged up for storage or transport and then unpacked by the program. An attacker who already holds an operator account can slip a doctored package into the system; when the server unpacks it, the attacker's code runs.

This is a deserialization of untrusted data flaw, catalogued as CWE-502. It scores 7.1 out of 10 on the CVSS v3.1 scale, which AVEVA rates as high but not critical, partly because the attacker needs a valid "DNA Authority - Operator" login and partly because the attack is complex to execute. Any code that does run executes with the privileges of the "DNA Apps" security group inside Enterprise SCADA, giving the attacker meaningful reach inside the control environment.

Which versions are affected?

Every supported release is affected. AVEVA has published a fixed build for each one.

Product Affected Fixed in
Enterprise SCADA 2025 2025 2025 P1 or higher
Enterprise SCADA 2024 up to 2024 SP1 P01 2024 SP1 P2
Enterprise SCADA 2023 up to 2023 SP1 2023 SP1 P1
Enterprise SCADA 2022 up to 2022 SP2 P2 2022 SP2 P3
Enterprise SCADA 2021 up to 2021 SP2 P5 2021 SP2 P6
Enterprise SCADA HMI up to 2024 R2, 2023 P1 2024 R2 HF7, 2023 P2 HF1

Pipeline Operations for Gas and Liquids, Pipeline Integrity Monitor and Measurement Advisor also receive matching updates.

Is patching enough?

No. Installing the update is only step one. Administrators must also change a configuration setting on the server: flip "BinarySerializer" from "Binary Formatter" to "Json", set "AcceptBinaryFormattedData" to false, and re-cache the XOS Event Handlers assembly. Clients connecting to Enterprise SCADA must be set to JSON only, and HMI (Human Machine Interface) displays, the graphical screens operators actually look at, need to be migrated. AVEVA's knowledge-base article KB117814 walks through the steps.

Should the public be worried?

Not immediately. There's no known exploitation in the wild, the attacker needs valid operator credentials, and the attack is rated as high complexity. The real risk is a rogue insider or an outsider who's already stolen an operator login through phishing, where criminals send fake emails to trick staff into surrendering passwords.

AVEVA advises operators to audit who holds the "DNA Authority - Operator" role and to keep test clients out of production networks. The vulnerability was reported to CISA by AVEVA itself, and fixes are available now through AVEVA support channels. What's worth watching is whether any of these pipeline deployments turn out to be running unsegmented networks where a compromised operator account could reach more than just the SCADA server.

© 2026 Threat Vectr