news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

HighCVSS 8.7
Summary

Rockwell Automation has released patches for over a dozen vulnerabilities affecting its industrial automation products, including several critical denial-of-service flaws. The company’s advisory highlights a significant risk due to potential code execution and privilege escalation vulnerabilities within its software and controllers, requiring immediate attention from customers to mitigate potential attacks.

Rockwell Automation announced on Tuesday that it has released patches and workarounds for numerous vulnerabilities found within its industrial automation products. The company’s advisory details a significant security risk stemming from several critical denial-of-service (DoS) issues impacting its software and controllers. Specifically, a critical DoS vulnerability exists in the RSLinx Classic communications software, which can cause the service to crash and necessitate a restart for recovery.

CISA’s own advisory for CVE-2026-9637, which covers a high-severity DoS flaw in ControlLogix and CompactLogix controllers, indicates that the agency is not currently aware of active exploitation of this vulnerability. However, Rockwell’s advisory explicitly states that the vulnerability is being exploited.

Beyond RSLinx Classic, Rockwell addressed DoS vulnerabilities in 1756-ENBT, Logix controllers (third-party component), and FactoryTalk Historian Machine Edition. A high-severity remote code execution issue was resolved within FactoryTalk Historian, while a flaw in FactoryTalk Activation Manager allows an authenticated attacker to access files, processes, and system resources with elevated privileges.

Furthermore, multiple XSS vulnerabilities have been patched in ArmorStart Distributed Motor Controllers, alongside a DoS issue affecting the web server. The ControlFLASH firmware management utility is vulnerable to an issue that could allow arbitrary code execution, granting an attacker the ability to run any commands or code on a target machine with the logged-in user’s permissions. Finally, a high-severity privilege escalation flaw affects the Redundancy Module Configuration Tool.

These vulnerabilities underscore the importance of promptly applying Rockwell’s security updates to minimize the risk of exploitation.

Read the full article at SecurityWeek