HackMyIP
← Back to News
2026-09-02 SecurityWeek

Rockwell Automation Patches Dozen-Plus Flaws Across ICS Product Line

VulnerabilityThreat Intel

Rockwell Automation disclosed patches and workarounds on Tuesday for more than a dozen vulnerabilities spanning its industrial automation portfolio, including critical and high-severity denial-of-service (DoS) flaws in the widely deployed RSLinx Classic communications software. Four of the most serious issues affect RSLinx Classic and can cause the service to crash, forcing an operator restart for recovery—a high-impact scenario in operational technology (OT) environments where uptime is critical. The advisories were coordinated with CISA, which published corresponding alerts to help asset owners and operators prioritize remediation.

One advisory stands out: CVE-2026-9637, a high-severity DoS flaw affecting ControlLogix and CompactLogix programmable logic controllers. Rockwell's document briefly flags the vulnerability as exploited in its header, though CISA and other sections of the advisory indicate no known exploitation—a discrepancy operators should review closely. Additional DoS issues were addressed in 1756-ENBT modules, third-party Logix controller components, and FactoryTalk Historian Machine Edition, where a high-severity remote code execution (RCE) flaw was also resolved. Operators managing exposed industrial networks can use a port scanner to identify reachable management interfaces before applying patches.

Beyond DoS, Rockwell patched a high-severity privilege escalation in FactoryTalk Activation Manager that lets an authenticated attacker access files, processes, and system resources with elevated rights. Multiple cross-site scripting (XSS) vulnerabilities enabling malicious script execution, plus a web server DoS flaw, were fixed in ArmorStart Distributed Motor Controllers. The ControlFLASH firmware management utility received a patch for a flaw allowing arbitrary code execution at the logged-in user's permission level, and the Redundancy Module Configuration Tool was updated to close a high-severity privilege escalation issue.

For organizations running Rockwell gear, the priority is inventorying RSLinx Classic, ControlLogix, and CompactLogix deployments and validating patch deployment or compensating controls. Network administrators should confirm that TLS configurations on web-facing components like ArmorStart and FactoryTalk are hardened—an SSL/TLS checker can surface weak ciphers or expired certificates that amplify exposure. With CISA's catalog of industrial control system advisories growing steadily, ICS defenders should also run a broader privacy checkup across connected assets to reduce the attack surface while patch cycles are completed.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →