Rockwell Patch Wave: DoS, RCE, and More
Rockwell Automation ships fixes for 13+ flaws, including critical RSLinx DoS and an exploited-tagged issue.
Industrial giant Rockwell Automation has a busy Tuesday. The company published a batch of advisories covering more than a dozen vulnerabilities across its product lines, from communications software to motor controllers. One advisory covers critical denial-of-service flaws. Another flags a vulnerability as exploited, though that label may be a mistake.
Critical DoS in RSLinx Classic
Only one of the new advisories describes critical vulnerabilities. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation can cause the RSLinx Classic service to crash, requiring a restart for recovery.
Exploited Flag Likely an Error
Rockwell's advisory for CVE-2026-9637, a high-severity DoS flaw in ControlLogix and CompactLogix controllers, flags the vulnerability as exploited. However, it's likely an error, as it's only listed as such in the document's header; elsewhere it's listed as not exploited.
CISA's own advisory for CVE-2026-9637, published by the agency on Tuesday along with other Rockwell advisories, also says it's not aware of exploitation.
DoS Fixes Across More Products
DoS vulnerabilities have also been addressed by Rockwell in 1756-ENBT, Logix controllers (third-party component), and FactoryTalk Historian Machine Edition.
RCE, Privilege Escalation, and More
In FactoryTalk Historian the company fixed a high-severity remote code execution issue. In FactoryTalk Activation Manager, Rockwell resolved a high-severity flaw that allows an authenticated attacker to access files, processes and system resources with elevated privileges.
Multiple XSS vulnerabilities that can lead to malicious script execution have been patched in ArmorStart Distributed Motor Controllers, along with a DoS issue impacting the web server.
The ControlFLASH firmware management utility is affected by a vulnerability that "could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker’s choice on a target machine at the logged-in user’s permission level."
The Redundancy Module Configuration Tool is affected by a high-severity privilege escalation flaw.
Why It Matters
Rockwell Automation is a major supplier of industrial control systems, and its gear runs in critical infrastructure environments like power plants and factories. While some of these flaws require authentication or local access, the breadth of the issues — from remote code execution to privilege escalation — shows that even small oversights in industrial products can have serious consequences. The exploited flag on CVE-2026-9637, even if erroneous, underscores that mislabeling can cause confusion among defenders trying to prioritize. For asset owners, the key takeaway is to review Rockwell's advisories, apply patches where available, and consider workarounds when immediate patching isn't possible.
Sources
- SecurityWeek Original source
Continue Reading
Sangoma Switchvox flaw exploited in active attacks
CVE-2026-9586, an unauthenticated SQL injection in Switchvox, is under active exploitation, Horizon3 reports.
AI Agents Cut Ransomware Timeline to Hours
A human attacker used AI agents to breach a network in under 10 hours, leaving an 80-page audit.
AI Exploits OT Equipment, But Not Cheaply
Forescout researchers used AI to port RCE exploits to PLCs, but high cost and effort still deter criminals.