Rockwell Automation on Tuesday informed customers that patches or workarounds are available for more than a dozen vulnerabilities discovered across its industrial automation products.
Only one of the new advisories describes critical vulnerabilities. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation can cause the RSLinx Classic service to crash, requiring a restart for recovery.
Rockwell’s advisory for CVE-2026-9637, a high-severity DoS flaw in ControlLogix and CompactLogix controllers, flags the vulnerability as exploited. However, it’s likely an error, as it’s only listed as such in the document’s header; elsewhere it’s listed as not exploited.
Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference
CISA’s own advisory for CVE-2026-9637, published by the agency on Tuesday along with other Rockwell advisories, also says it’s not aware of exploitation.
DoS vulnerabilities have also been addressed by Rockwell in 1756-ENBT, Logix controllers (third-party component), and FactoryTalk Historian Machine Edition.
In FactoryTalk Historian the company fixed a high-severity remote code execution issue. In FactoryTalk Activation Manager, Rockwell resolved a high-severity flaw that allows an authenticated attacker to access files, processes and system resources with elevated privileges.
Multiple XSS vulnerabilities that can lead to malicious script execution have been patched in ArmorStart Distributed Motor Controllers, along with a DoS issue impacting the web server.
The ControlFLASH firmware management utility is affected by a vulnerability that “could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker’s choice on a target machine at the logged-in user’s permission level.”
The Redundancy Module Configuration Tool is affected by a high-severity privilege escalation flaw.
Related: Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars
Related: Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear
Related: CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks


