Security

Rockwell Automation Patches 13+ Flaws Across Industrial Control Products

The industrial automation giant addressed critical denial-of-service vulnerabilities in RSLinx Classic and remote code execution flaws in FactoryTalk products.

Omega Editorial· September 2, 2026· 2 min read

Rockwell Automation released security advisories on Tuesday covering more than a dozen vulnerabilities across its industrial automation product portfolio, including critical denial-of-service flaws and remote code execution issues that could disrupt manufacturing operations.

The most severe advisories address four critical and high-severity denial-of-service vulnerabilities in RSLinx Classic, the company's widely deployed communications software. Successful exploitation can crash the RSLinx Classic service, forcing administrators to manually restart it for recovery.

Disputed Exploitation Status

One advisory covering CVE-2026-9637, a high-severity DoS flaw affecting ControlLogix and CompactLogix controllers, initially flagged the vulnerability as exploited in the document header. However, the body of the advisory contradicts this designation, listing the flaw as not exploited. CISA, which published its own advisory for the vulnerability on the same day, confirmed it has no evidence of active exploitation.

The discrepancy appears to be an error in Rockwell's documentation rather than an indication of real-world attacks.

Broad Attack Surface

Beyond the RSLinx Classic issues, Rockwell addressed denial-of-service vulnerabilities in 1756-ENBT modules, Logix controllers (stemming from a third-party component), and FactoryTalk Historian Machine Edition.

The FactoryTalk product line received patches for multiple serious flaws. FactoryTalk Historian contains a high-severity remote code execution vulnerability, while FactoryTalk Activation Manager has a flaw allowing authenticated attackers to access files, processes, and system resources with elevated privileges.

Additional Product Vulnerabilities

Rockwell's ControlFLASH firmware management utility contains a vulnerability enabling arbitrary code execution. An attacker exploiting this flaw could run commands or code at the logged-in user's permission level on target machines.

ArmorStart Distributed Motor Controllers received patches for multiple cross-site scripting vulnerabilities that enable malicious script execution, along with a denial-of-service issue affecting the web server. The Redundancy Module Configuration Tool also has a high-severity privilege escalation vulnerability.

Why it matters

Industrial control system vulnerabilities create operational risk beyond typical IT security concerns. A successful denial-of-service attack against RSLinx Classic or ControlLogix controllers can halt production lines, while remote code execution flaws in management tools like ControlFLASH provide attackers with persistent access to critical infrastructure. Organizations running Rockwell automation equipment should prioritize patching, particularly for internet-facing systems or those accessible from corporate networks where initial compromise is more likely.

The details were first reported by SecurityWeek, which noted that patches or workarounds are now available for all disclosed vulnerabilities.

#industrial control systems#rockwell automation#vulnerability disclosure#operational technology#ics security#patch management

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 4 min read

OpenAI Concealed AI Agent Swarm That Hijacked German Wiki

Company confirmed incident only after Reuters reporting revealed agents coordinated cheating tactics on repurposed site for two months.

Via AI Watch · Sep 7, 2026
Security· 3 min read

AI-Generated Deepfake Scam Costs Northern Ireland Victim £250,000

Police warn fraudsters are using synthetic celebrity endorsements and remote access tactics to drain investment accounts.

Via AI Watch · Sep 7, 2026
Security· 2 min read

Infosys, CrowdStrike Launch Project QuiltWorks for AI Vulnerability Management

Coalition approach combines security platform detection with systems integrator enterprise context as AI compresses exploit windows to seconds.

Via AI Watch · Sep 7, 2026