Rockwell Automation Patches a Dozen Vulnerabilities Across RSLinx, Logix, and FactoryTalk

Rockwell Automation vulnerabilities in RSLinx Classic and Logix industrial controllers

Rockwell Automation has closed more than a dozen vulnerabilities in software and controllers used at industrial facilities. The gravest of these flaws permit the disabling of control-system components, the execution of code on a device, or the acquisition of SYSTEM privileges in Windows. The problems therefore afflict not merely engineers’ workstations, but also equipment directly engaged in governing production processes.

Four Flaws in RSLinx Classic Lead the List

Most serious of all is a set of four flaws in RSLinx Classic, through which Rockwell Automation applications exchange data with Allen-Bradley devices. The vulnerabilities CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, and CVE-2026-9625 allow specially crafted packets of the industrial CIP protocol to crash the RSLinx service. To recover, the operator must restart the service. Two of the flaws received 9.2 out of 10 under CVSS 4.0, and the other two, 8.7.

A Kindred Fault in the Logix Controllers

A similar problem, CVE-2026-9637, has been found directly in the ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 controllers. An improperly formed CIP message can trigger a denial of service and cast the controller into a Major Nonrecoverable Fault state. Merely restoring the connection does not suffice; returning the equipment to service requires a power cycle. Rockwell rated CVE-2026-9637 at 8.7 under CVSS 4.0 and released corrected firmware versions 34.015, 35.014, 36.013, and 37.011.

Confusion arose over the exploitation status of CVE-2026-9637. The header of Rockwell’s bulletin bears a “Known Exploited Vulnerability” mark, yet in the technical description on the same page the company states that no known attacks exist. CISA, too, has reported no confirmed exploitation. CVE-2026-9637 cannot, therefore, be regarded as already used in real-world attacks.

A Discontinued Ethernet Module Left Without a Fix

A separate vulnerability, CVE-2026-84235, affects all versions of the industrial Ethernet module 1756-ENBT. A single specially prepared CIP packet can crash the module, after which a restart is required. No corrected firmware for the 1756-ENBT will be issued, as the product has been discontinued. Rockwell recommends migrating to the newer 1756-EN2T or 1756-EN4TR.

Remote Code Execution in FactoryTalk Historian

In FactoryTalk Historian Machine Edition, the consequences may be graver still. The vulnerability CVE-2025-12768, scored 8.6, allows a user with minimal privileges to achieve remote code execution on the Historian ME module. A second flaw, CVE-2026-12661, allows an authenticated user from an adjacent network segment to send specially crafted requests to the web interface, provoke a buffer overflow, and render the device unreachable. Rockwell corrected both problems in versions 7.102 for Series C and 5.203 for Series B.

Two Classes of Flaw in ArmorStart LT

Two distinct classes of problem were found in ArmorStart LT. Several flaws under CVE-2026-19471 permit the injection of stored XSS, whereby a malicious script is preserved on the device and executed in another user’s browser upon opening the infected page. CVE-2026-19472 allows a specially crafted HTTP PUT request to disable the embedded web server. Both problems are corrected in ArmorStart LT 2.002.

Privilege Escalation in FactoryTalk Activation Manager

The vulnerability CVE-2026-16675 in FactoryTalk Activation Manager opens another avenue of attack. During product installation or repair, certain operations launch a visible console window with SYSTEM privileges. A user who already holds a Windows account on the machine can hijack such a console and gain full access to files, processes, and system resources. Rockwell closed this privilege escalation in FactoryTalk Activation Manager 5.03.

DLL-Loading Flaws in the Redundancy Configuration Tool

Two further vulnerabilities, CVE-2026-9633 and CVE-2026-9634, concern DLL loading in the Redundancy Module Configuration Tool. The utilities RM3ConfigTool.exe and RMConfigTool.exe may seek the required library in directories writable by an ordinary user. A local attacker can place a malicious DLL there, wait for an administrator to launch the program, and execute code with Administrator or SYSTEM privileges. The vulnerable versions were updated to 10.01.00.

An Over-Permissive Installer in ControlFLASH

Finally, in ControlFLASH, used to update the firmware of controllers and other Allen-Bradley devices, the installer granted overly broad permissions to the program directory. CVE-2026-12663 allows a local user to substitute the directory’s contents and achieve arbitrary code execution with the privileges of the logged-in user. The flaw was resolved in ControlFLASH 15.08. For systems that cannot yet be updated, the manufacturer suggests removing the Everyone group from the list of users with access to the program directory.

No Mass Exploitation Yet, but the Stakes Are Higher

There is as yet no confirmation of mass exploitation of the vulnerabilities published on September 1. For industrial infrastructure, however, even an ordinary DoS carries graver consequences than the crash of a user application. A vulnerable component may serve communication with controllers or itself govern a technological process, and the recovery of some devices demands a physical restart. Rockwell recommends installing the corrected versions, not exposing controllers directly to the internet, and separating the industrial network from the corporate infrastructure.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply