Industrial automation leader Rockwell Automation has issued patches and workarounds for more than a dozen vulnerabilities across its product portfolio. The fixes address critical denial‑of‑service and remote code execution issues in RSLinx Classic, FactoryTalk, and controller firmware.
- Rockwell released patches for 12+ security flaws
- Critical DoS and RCE issues found in RSLinx Classic and FactoryTalk
- CISA acknowledges the flaws but reports no confirmed exploitation
Comprehensive Security Update
Rockwell Automation informed customers on Tuesday that patches or workarounds are now available for more than a dozen vulnerabilities discovered across its industrial automation suite. Only one advisory describes a critical flaw, while the rest cover high‑severity denial‑of‑service (DoS) problems.
RSLinx Classic communications software is affected by four critical and high‑severity DoS issues that can crash the service, forcing a restart. Additionally, a high‑severity DoS flaw (CVE‑2026‑9637) in ControlLogix and CompactLogix controllers is flagged as exploited in the advisory, though the document later lists it as not exploited.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released its own advisory for CVE‑2026‑9637, stating it is unaware of any exploitation. DoS vulnerabilities were also addressed in 1756‑ENBT, Logix controllers (third‑party component), and FactoryTalk Historian Machine Edition.
Other High‑Severity Flaws
FactoryTalk Historian received a fix for a high‑severity remote code execution (RCE) issue. FactoryTalk Activation Manager saw a high‑severity flaw patched that allowed an authenticated attacker to access files, processes, and system resources with elevated privileges.
Multiple XSS (cross‑site scripting) vulnerabilities in ArmorStart Distributed Motor Controllers were patched, along with a DoS issue affecting its web server. The ControlFLASH firmware management utility had a vulnerability that could allow arbitrary code execution at the logged‑in user’s permission level. The Redundancy Module Configuration Tool was also patched for a high‑severity privilege‑escalation flaw.
Historical Background
Industrial Control Systems (ICS) and Operational Technology (OT) security have faced high‑profile attacks in recent years, such as the 2021 Colonial Pipeline ransomware incident and the 2020 SolarWinds supply‑chain breach. These events highlighted the necessity for continuous vulnerability management and timely patch deployment in industrial software.
Why This Matters
BozokMedia analysis shows that proactive patching by major industrial software vendors like Rockwell is essential for maintaining global supply‑chain continuity and preventing costly production downtime. Exploitation of these flaws could lead to widespread service interruptions or data breaches.
"Prioritizing security in every layer of industrial automation is no longer optional—it’s mandatory," says cybersecurity expert Dr. Anjali Singh.
Frequently Asked Questions
Q1: Do I need additional licenses to apply these patches?
A: No, Rockwell provides the updates free of charge to existing license holders.
Q2: Can I obtain the patches if my system is air‑gapped?
A: Yes, Rockwell also offers offline update packages for isolated environments.