AVEVA disclosed seven vulnerabilities in AVEVA Process Optimization (formerly ROMeo) affecting version 2024.1 and earlier, including a CVSS v4.0 10.0 issue, CVE-2025-61937, that enables unauthenticated remote code execution as OS SYSTEM. The flaw is described as a code injection vulnerability in the application’s API layer and can allow remote attackers with network access to execute arbitrary code under the taoimr service context, potentially leading to full compromise of the Model Application Server and connected industrial modeling infrastructure; the attack is characterized as remote, low-complexity, and requiring no user interaction.
Additional high-severity issues reported alongside the RCE include CVE-2025-64691 (macro/TCL script tampering enabling authenticated privilege escalation to SYSTEM), CVE-2025-61943 (SQL injection in the Captive Historian component that can lead to SQL Server administrative access and code execution), and other critical/high findings such as DLL hijacking (CVE-2025-65118), missing ACLs (CVE-2025-64729), embedded OLE object risks (CVE-2025-65117), and cleartext transmission exposure (CVE-2025-64769). AVEVA’s bulletin emphasizes that multiple paths exist to compromise affected servers—either directly via the unauthenticated API RCE or via authenticated user-to-SYSTEM escalation—raising immediate risk for organizations operating vulnerable industrial process optimization deployments.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Alongside the disclosure, AVEVA advised customers to upgrade to AVEVA Process Optimization 2025 or later to remediate the issues. For organizations unable to patch immediately, it recommended restricting network access to the taoimr service, tightening folder ACLs, and maintaining strict controls over project files and change management.
On 2026-01-13, AVEVA disclosed seven vulnerabilities affecting AVEVA Process Optimization 2024.1 and earlier. The most severe, CVE-2025-61937, is an unauthenticated API remote code execution flaw rated CVSS 10.0 that could allow full compromise of the Model Application Server.
During a planned penetration test, Veracode researcher Christopher Wu discovered seven vulnerabilities in AVEVA Process Optimization (formerly ROMeo), including issues that could enable remote code execution, privilege escalation, SQL injection, and other attacks. The findings were coordinated with CISA.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.