AVEVA disclosed a critical deserialization of untrusted data vulnerability in Enterprise SCADA tracked as CVE-2025-7639, a remotely exploitable flaw with a CVSS 4.0 score of 10.0. The issue allows an authenticated attacker holding the "DNA Authority - Operator" privilege to tamper with serialized data and potentially trigger code execution during deserialization under the privileges of the "DNA Apps" security group.
The vendor addressed the issue in security bulletin AVEVA-2026-005 and advised organizations to apply available patches and hardening measures. Recommended mitigations include restricting operator privileges and validating serialized data inputs, as the flaw affects industrial control and supervisory environments where compromise of SCADA application privileges could materially increase operational risk.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A critical deserialization of untrusted data vulnerability, CVE-2025-7639, was disclosed for AVEVA Enterprise SCADA. The flaw is rated CVSS 4.0 10.0 and could allow an authenticated attacker with "DNA Authority - Operator" privileges to achieve code execution under the "DNA Apps" security group context.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.