ICS/OT

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Rockwell Automation vulnerabilities

Rockwell Automation on Tuesday informed customers that patches or workarounds are available for more than a dozen vulnerabilities discovered across its industrial automation products.

Only one of the new advisories describes critical vulnerabilities. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation can cause the RSLinx Classic service to crash, requiring a restart for recovery.

Rockwell’s advisory for CVE-2026-9637, a high-severity DoS flaw in ControlLogix and CompactLogix controllers, flags the vulnerability as exploited. However, it’s likely an error, as it’s only listed as such in the document’s header; elsewhere it’s listed as not exploited.

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

CISA’s own advisory for CVE-2026-9637, published by the agency on Tuesday along with other Rockwell advisories, also says it’s not aware of exploitation.

DoS vulnerabilities have also been addressed by Rockwell in 1756-ENBT, Logix controllers (third-party component), and FactoryTalk Historian Machine Edition.

Advertisement. Scroll to continue reading.

In FactoryTalk Historian the company fixed a high-severity remote code execution issue. In FactoryTalk Activation Manager, Rockwell resolved a high-severity flaw that allows an authenticated attacker to access files, processes and system resources with elevated privileges.

Multiple XSS vulnerabilities that can lead to malicious script execution have been patched in ArmorStart Distributed Motor Controllers, along with a DoS issue impacting the web server.

The ControlFLASH firmware management utility is affected by a vulnerability that “could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker’s choice on a target machine at the logged-in user’s permission level.”

The Redundancy Module Configuration Tool is affected by a high-severity privilege escalation flaw. 

Related: Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars

Related: Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear

Related: CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

Related Content

Vulnerabilities

The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.

Vulnerabilities

The security defect allows remote attackers to bypass authentication through argument bearer manipulation.

Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

Vulnerabilities

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

Artificial Intelligence

Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models.

Artificial Intelligence

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Vulnerabilities

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version