CISA has published an advisory for two vulnerabilities affecting Rockwell Automation Historian ME (FactoryTalk Historian Machine Edition) in Series B 5.202 and Series C 7.101. CVE-2025-12768 is a high-severity out-of-bounds write vulnerability (CVSS 3.1: 8.0) that allows a low-privileged, network-adjacent attacker to achieve remote code execution. CVE-2026-12661 is a medium-severity stack-based buffer overflow (CVSS 3.1: 4.5) that enables an authenticated adjacent attacker to crash the device via crafted web requests, causing denial of service. Affected critical infrastructure sectors include Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, and Water and Wastewater Systems. No public exploitation has been reported. Mitigations include following Rockwell Automation security best practices, minimizing network exposure, using firewalls, and employing VPNs for remote access. Rockwell Automation self-reported these vulnerabilities to CISA.