Close Menu
NCIJ Network NCIJ Network
    What's Hot

    New UK taskforce will examine influence of political mega-donors | Politics

    September 2, 2026

    Dutch central bank moves gold bars out of New York over ‘geopolitical unrest’

    September 2, 2026

    1Password wades into a right-wing mess after funding a Linux project

    September 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • New UK taskforce will examine influence of political mega-donors | Politics
    • Dutch central bank moves gold bars out of New York over ‘geopolitical unrest’
    • 1Password wades into a right-wing mess after funding a Linux project
    • Google DeepMind Releases Gemini 3.8 Flash and Gemini 3.8 Flash Cyber: One Core Model, Two Access Envelopes
    • Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
    • New Jersey Officials Petition US Supreme Court over Prediction Markets
    • Interstellar solar sails hit a strange problem at 75% of light speed
    • Why Montana Firefighters Are Intentionally Burning Areas Around Two Wildfires
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 2, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Rockwell Automation on Tuesday informed customers that patches or workarounds are available for more than a dozen vulnerabilities discovered across its industrial automation products.

    Only one of the new advisories describes critical vulnerabilities. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation can cause the RSLinx Classic service to crash, requiring a restart for recovery.

    Rockwell’s advisory for CVE-2026-9637, a high-severity DoS flaw in ControlLogix and CompactLogix controllers, flags the vulnerability as exploited. However, it’s likely an error, as it’s only listed as such in the document’s header; elsewhere it’s listed as not exploited.

    Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

    CISA’s own advisory for CVE-2026-9637, published by the agency on Tuesday along with other Rockwell advisories, also says it’s not aware of exploitation.

    DoS vulnerabilities have also been addressed by Rockwell in 1756-ENBT, Logix controllers (third-party component), and FactoryTalk Historian Machine Edition.

    Advertisement. Scroll to continue reading.

    In FactoryTalk Historian the company fixed a high-severity remote code execution issue. In FactoryTalk Activation Manager, Rockwell resolved a high-severity flaw that allows an authenticated attacker to access files, processes and system resources with elevated privileges.

    Multiple XSS vulnerabilities that can lead to malicious script execution have been patched in ArmorStart Distributed Motor Controllers, along with a DoS issue impacting the web server.

    The ControlFLASH firmware management utility is affected by a vulnerability that “could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker’s choice on a target machine at the logged-in user’s permission level.”

    The Redundancy Module Configuration Tool is affected by a high-severity privilege escalation flaw. 

    Related: Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars

    Related: Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear

    Related: CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

    Automation Dozen Patches products Rockwell Vulnerabilities
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

    UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

    Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

    Ransomware protection for MSPs: A 6-point checklist for faster recovery

    Microsoft Defender flags legitimate Google search links as malicious

    Dropbox accounts breached through Lenovo email verification flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    New UK taskforce will examine influence of political mega-donors | Politics

    September 2, 2026

    Dutch central bank moves gold bars out of New York over ‘geopolitical unrest’

    September 2, 2026

    1Password wades into a right-wing mess after funding a Linux project

    September 2, 2026

    Google DeepMind Releases Gemini 3.8 Flash and Gemini 3.8 Flash Cyber: One Core Model, Two Access Envelopes

    September 2, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    New UK taskforce will examine influence of political mega-donors | Politics

    September 2, 2026

    Dutch central bank moves gold bars out of New York over ‘geopolitical unrest’

    September 2, 2026

    1Password wades into a right-wing mess after funding a Linux project

    September 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.