Breaking
SecurityConfirmed

Rockwell Patch Wave: DoS, RCE, and More

Rockwell Automation ships fixes for 13+ flaws, including critical RSLinx DoS and an exploited-tagged issue.

··2 hours ago·2 min read
aerial view of industrial factory
Photo by CHUTTERSNAP on Unsplash

Industrial giant Rockwell Automation has a busy Tuesday. The company published a batch of advisories covering more than a dozen vulnerabilities across its product lines, from communications software to motor controllers. One advisory covers critical denial-of-service flaws. Another flags a vulnerability as exploited, though that label may be a mistake.

Critical DoS in RSLinx Classic

Only one of the new advisories describes critical vulnerabilities. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation can cause the RSLinx Classic service to crash, requiring a restart for recovery.

Exploited Flag Likely an Error

Rockwell's advisory for CVE-2026-9637, a high-severity DoS flaw in ControlLogix and CompactLogix controllers, flags the vulnerability as exploited. However, it's likely an error, as it's only listed as such in the document's header; elsewhere it's listed as not exploited.

CISA's own advisory for CVE-2026-9637, published by the agency on Tuesday along with other Rockwell advisories, also says it's not aware of exploitation.

DoS Fixes Across More Products

DoS vulnerabilities have also been addressed by Rockwell in 1756-ENBT, Logix controllers (third-party component), and FactoryTalk Historian Machine Edition.

RCE, Privilege Escalation, and More

In FactoryTalk Historian the company fixed a high-severity remote code execution issue. In FactoryTalk Activation Manager, Rockwell resolved a high-severity flaw that allows an authenticated attacker to access files, processes and system resources with elevated privileges.

Multiple XSS vulnerabilities that can lead to malicious script execution have been patched in ArmorStart Distributed Motor Controllers, along with a DoS issue impacting the web server.

The ControlFLASH firmware management utility is affected by a vulnerability that "could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker’s choice on a target machine at the logged-in user’s permission level."

The Redundancy Module Configuration Tool is affected by a high-severity privilege escalation flaw.

Why It Matters

Rockwell Automation is a major supplier of industrial control systems, and its gear runs in critical infrastructure environments like power plants and factories. While some of these flaws require authentication or local access, the breadth of the issues — from remote code execution to privilege escalation — shows that even small oversights in industrial products can have serious consequences. The exploited flag on CVE-2026-9637, even if erroneous, underscores that mislabeling can cause confusion among defenders trying to prioritize. For asset owners, the key takeaway is to review Rockwell's advisories, apply patches where available, and consider workarounds when immediate patching isn't possible.

#rockwell-automation#ics-vulnerabilities#denial-of-service#cve-2026-9637#rslinx#patch-tuesday

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories