High severityNVD Advisory· Published Jul 14, 2026· Updated Jul 14, 2026
CVE-2026-9653
CVE-2026-9653
Description
A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.
Affected products
3Patches
Vulnerability mechanics
References
1News mentions
2- Rockwell Automation: 11 Vulnerabilities Disclosed, Including Critical Flaw in EtherNet/IP AdapterVypr Intelligence · Jul 16, 2026
- Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBTCISA Alerts