Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
Rockwell Automation releases patches for over a dozen vulnerabilities across multiple industrial automation products.
Summary
Rockwell Automation has issued advisories for over a dozen vulnerabilities affecting its industrial automation products, including RSLinx Classic, ArmorStart, and FactoryTalk. While most issues are high-severity, one advisory details critical and high-severity denial-of-service flaws in RSLinx Classic. A separate advisory flags a DoS vulnerability in ControlLogix and CompactLogix controllers as potentially exploited, though this claim is disputed.
Full text
Rockwell Automation on Tuesday informed customers that patches or workarounds are available for more than a dozen vulnerabilities discovered across its industrial automation products. Only one of the new advisories describes critical vulnerabilities. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation can cause the RSLinx Classic service to crash, requiring a restart for recovery. Rockwell’s advisory for CVE-2026-9637, a high-severity DoS flaw in ControlLogix and CompactLogix controllers, flags the vulnerability as exploited. However, it’s likely an error, as it’s only listed as such in the document’s header; elsewhere it’s listed as not exploited. Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference CISA’s own advisory for CVE-2026-9637, published by the agency on Tuesday along with other Rockwell advisories, also says it’s not aware of exploitation. DoS vulnerabilities have also been addressed by Rockwell in 1756-ENBT, Logix controllers (third-party component), and FactoryTalk Historian Machine Edition.Advertisement. Scroll to continue reading. In FactoryTalk Historian the company fixed a high-severity remote code execution issue. In FactoryTalk Activation Manager, Rockwell resolved a high-severity flaw that allows an authenticated attacker to access files, processes and system resources with elevated privileges. Multiple XSS vulnerabilities that can lead to malicious script execution have been patched in ArmorStart Distributed Motor Controllers, along with a DoS issue impacting the web server. The ControlFLASH firmware management utility is affected by a vulnerability that “could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker’s choice on a target machine at the logged-in user’s permission level.” The Redundancy Module Configuration Tool is affected by a high-severity privilege escalation flaw. Related: Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars Related: Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear Related: CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of DollarsCritical JFrog Artifactory Vulnerability Reportedly Exploited in the WildPaperCut Exploitation Escalates to Active IntrusionsNightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product ExploitAnthropic Warns Claude Users of Infostealer Malware InfectionsBoston Scientific Still Recovering From CyberattackMore Details Emerge on Exploited PaperCut VulnerabilitiesHasbro Data Breach Exposed Employee Personal Information Latest News Exploit Published for Fresh Cleo Harmony VulnerabilityAnthropic Details Response to Security Incidents, Unveils Enterprise SafeguardsMalicious Virtualizor Update Served via BGP HijackingOpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-DaysChrome and Firefox Updates Patch Dozens of Vulnerabilities23-Year-Old Sality P2P Botnet DisruptedSonicWall Warns of Two SMA1000 Zero-Days Exploited in AttacksPalo Alto Networks Acquires AI Agent Platform Console Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTom Bonos has been named Chief Revenue Officer at Sumo Logic.Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-9637