news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation ArmorStart LT

HighCVSS 8.7
Summary

Rockwell Automation has released a security advisory regarding critical cross-site scripting vulnerabilities in its ArmorStart LT firmware. Versions <=v2.001 are affected, leading to potential denial-of-service and injection of malicious scripts. Rockwell Automation has provided a fix in firmware version v2.002, and users are strongly urged to update immediately. CISA recommends minimizing network exposure and utilizing secure remote access methods.

Rockwell Automation has identified and announced critical cross-site scripting vulnerabilities within its ArmorStart LT firmware. These vulnerabilities, identified as CVE-2026-19471 and CVE-2026-19472, could allow an attacker to inject malicious scripts when other users access the affected page, potentially leading to a denial-of-service and compromise of the web server. The affected product is Rockwell Automation ArmorStart LT, specifically versions equal to or less than v2.001.

CISA recommends that organizations immediately update to firmware version v2.002 to mitigate these risks. For users unable to upgrade, Rockwell Automation advises following their security best practices.

CISA is also urging organizations to implement defensive measures, including minimizing network exposure for control system devices, isolating them from business networks, and utilizing secure remote access methods such as VPNs (recognizing that VPNs themselves can have vulnerabilities). Organizations should perform thorough impact analysis and risk assessments before deploying any defensive strategies.

At this time, no public exploitation specifically targeting these vulnerabilities has been reported to CISA.

Read the full article at CISA Advisories