Rockwell Automation Patches 13+ Flaws Across Industrial Control Products
The industrial automation giant addressed critical denial-of-service vulnerabilities in RSLinx Classic and remote code execution flaws in FactoryTalk products.
Rockwell Automation released security advisories on Tuesday covering more than a dozen vulnerabilities across its industrial automation product portfolio, including critical denial-of-service flaws and remote code execution issues that could disrupt manufacturing operations.
The most severe advisories address four critical and high-severity denial-of-service vulnerabilities in RSLinx Classic, the company's widely deployed communications software. Successful exploitation can crash the RSLinx Classic service, forcing administrators to manually restart it for recovery.
Disputed Exploitation Status
One advisory covering CVE-2026-9637, a high-severity DoS flaw affecting ControlLogix and CompactLogix controllers, initially flagged the vulnerability as exploited in the document header. However, the body of the advisory contradicts this designation, listing the flaw as not exploited. CISA, which published its own advisory for the vulnerability on the same day, confirmed it has no evidence of active exploitation.
The discrepancy appears to be an error in Rockwell's documentation rather than an indication of real-world attacks.
Broad Attack Surface
Beyond the RSLinx Classic issues, Rockwell addressed denial-of-service vulnerabilities in 1756-ENBT modules, Logix controllers (stemming from a third-party component), and FactoryTalk Historian Machine Edition.
The FactoryTalk product line received patches for multiple serious flaws. FactoryTalk Historian contains a high-severity remote code execution vulnerability, while FactoryTalk Activation Manager has a flaw allowing authenticated attackers to access files, processes, and system resources with elevated privileges.
Additional Product Vulnerabilities
Rockwell's ControlFLASH firmware management utility contains a vulnerability enabling arbitrary code execution. An attacker exploiting this flaw could run commands or code at the logged-in user's permission level on target machines.
ArmorStart Distributed Motor Controllers received patches for multiple cross-site scripting vulnerabilities that enable malicious script execution, along with a denial-of-service issue affecting the web server. The Redundancy Module Configuration Tool also has a high-severity privilege escalation vulnerability.
Why it matters
Industrial control system vulnerabilities create operational risk beyond typical IT security concerns. A successful denial-of-service attack against RSLinx Classic or ControlLogix controllers can halt production lines, while remote code execution flaws in management tools like ControlFLASH provide attackers with persistent access to critical infrastructure. Organizations running Rockwell automation equipment should prioritize patching, particularly for internet-facing systems or those accessible from corporate networks where initial compromise is more likely.
The details were first reported by SecurityWeek, which noted that patches or workarounds are now available for all disclosed vulnerabilities.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call
