Rockwell Automation fixes over a dozen vulnerabilities across all products

Rockwell Automation fixes over a dozen vulnerabilities across all products

Rockwell Automation informed customers on Tuesday that patches or workarounds are available for more than a dozen vulnerabilities discovered in its industrial automation products.

Just one of the new ones Notes describes critical vulnerabilities. It addresses four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation may cause the RSLinx Classic service to crash and require a reboot to recover.

Rockwell’s advice for CVE-2026-9637a high-severity DoS flaw in ControlLogix and CompactLogix controllers, flags the vulnerability as exploited. However, it is probably an error as it is only listed as such in the header of the document. Elsewhere it is listed as unexploited.

Practical cyber-physical systems training at the ICS Cybersecurity Conference

CISA’s own advice for CVE-2026-9637, released by the agency on Tuesday along with other Rockwell Advisorys also says it is unaware of the exploitation.

Rockwell also addressed DoS vulnerabilities in 1756-ENBT, Logix controllers (third-party component), and FactoryTalk Historian Machine Edition.

Advertising. Scroll to continue reading.

In FactoryTalk Historian, the company fixed a serious remote code execution issue. In FactoryTalk Activation Manager, Rockwell has fixed a fatal flaw that allows an authenticated attacker to access files, processes, and system resources with elevated privileges.

Multiple XSS vulnerabilities that could lead to the execution of malicious scripts have been fixed in ArmorStart Distributed Motor Controllers, along with a DoS issue affecting the web server.

The firmware management utility ControlFLASH is affected by a vulnerability that “could allow arbitrary code execution, resulting in an attacker having the ability to execute arbitrary commands or code of their choice on a target computer with the privilege level of the logged in user.”

The Redundancy Module Configuration Tool is affected by a fatal privilege escalation flaw.

Related: Experiment: Porting a PLC exploit with AI takes hours and hundreds of dollars

Related: Trump Order Aims to Block Foreign Backdoors in US Power Grid Equipment

Related: CISA: July cyberattacks targeted over 100 cyber-vulnerable water systems

Leave a Reply

Your email address will not be published. Required fields are marked *