Rockwell Automation Addresses Over a Dozen Vulnerabilities Across Industrial Products
Rockwell Automation has released patches and workarounds for more than a dozen vulnerabilities affecting its industrial automation software and hardware, including critical flaws in RSLinx Classic.

Rockwell Automation has issued security advisories detailing patches and workarounds for over a dozen vulnerabilities discovered across its range of industrial automation products. These updates address critical security flaws within software and hardware, urging customers to apply them promptly to mitigate potential risks.
The most severe issues are four critical and high-severity denial-of-service (DoS) vulnerabilities affecting the RSLinx Classic communications software. Exploitation of these flaws can cause the RSLinx Classic service to crash, necessitating a manual restart for recovery.
One advisory, for CVE-2026-9637, flags a high-severity DoS vulnerability in ControlLogix and CompactLogix controllers as exploited. However, this appears to be an error in the advisory's header, as other sections and CISA's own advisory indicate no known exploitation for this specific flaw.
Additional DoS vulnerabilities have been addressed by Rockwell in other products, including the 1756-ENBT, Logix controllers (via a third-party component), and FactoryTalk Historian Machine Edition. These DoS issues could disrupt the normal operation of critical industrial control systems.
In FactoryTalk Historian, the company has also resolved a high-severity remote code execution (RCE) issue. Furthermore, a high-severity vulnerability in FactoryTalk Activation Manager allows an authenticated attacker to gain elevated privileges, enabling them to access files, processes, and system resources with greater authority.
Multiple cross-site scripting (XSS) vulnerabilities have been patched in ArmorStart Distributed Motor Controllers. These flaws could lead to the execution of malicious scripts, potentially compromising user sessions or injecting harmful content. A DoS issue impacting the web server of these controllers has also been fixed.
The ControlFLASH firmware management utility is affected by a vulnerability that could permit arbitrary code execution. This would grant an attacker the ability to run any commands or code on a target machine with the same permissions as the logged-in user, posing a significant risk to system integrity.
Lastly, the Redundancy Module Configuration Tool suffers from a high-severity privilege escalation flaw, allowing local attackers to potentially gain higher-level access to the system.