Security

Rockwell Automation Patches 13+ Flaws Across Industrial Control Products

The industrial automation giant addressed critical denial-of-service vulnerabilities in RSLinx Classic and remote code execution flaws in FactoryTalk products.

Omega Editorial· September 2, 2026· 2 min read

Rockwell Automation released security advisories on Tuesday covering more than a dozen vulnerabilities across its industrial automation product portfolio, including critical denial-of-service flaws and remote code execution issues that could disrupt manufacturing operations.

The most severe advisories address four critical and high-severity denial-of-service vulnerabilities in RSLinx Classic, the company's widely deployed communications software. Successful exploitation can crash the RSLinx Classic service, forcing administrators to manually restart it for recovery.

Disputed Exploitation Status

One advisory covering CVE-2026-9637, a high-severity DoS flaw affecting ControlLogix and CompactLogix controllers, initially flagged the vulnerability as exploited in the document header. However, the body of the advisory contradicts this designation, listing the flaw as not exploited. CISA, which published its own advisory for the vulnerability on the same day, confirmed it has no evidence of active exploitation.

The discrepancy appears to be an error in Rockwell's documentation rather than an indication of real-world attacks.

Broad Attack Surface

Beyond the RSLinx Classic issues, Rockwell addressed denial-of-service vulnerabilities in 1756-ENBT modules, Logix controllers (stemming from a third-party component), and FactoryTalk Historian Machine Edition.

The FactoryTalk product line received patches for multiple serious flaws. FactoryTalk Historian contains a high-severity remote code execution vulnerability, while FactoryTalk Activation Manager has a flaw allowing authenticated attackers to access files, processes, and system resources with elevated privileges.

Additional Product Vulnerabilities

Rockwell's ControlFLASH firmware management utility contains a vulnerability enabling arbitrary code execution. An attacker exploiting this flaw could run commands or code at the logged-in user's permission level on target machines.

ArmorStart Distributed Motor Controllers received patches for multiple cross-site scripting vulnerabilities that enable malicious script execution, along with a denial-of-service issue affecting the web server. The Redundancy Module Configuration Tool also has a high-severity privilege escalation vulnerability.

Why it matters

Industrial control system vulnerabilities create operational risk beyond typical IT security concerns. A successful denial-of-service attack against RSLinx Classic or ControlLogix controllers can halt production lines, while remote code execution flaws in management tools like ControlFLASH provide attackers with persistent access to critical infrastructure. Organizations running Rockwell automation equipment should prioritize patching, particularly for internet-facing systems or those accessible from corporate networks where initial compromise is more likely.

The details were first reported by SecurityWeek, which noted that patches or workarounds are now available for all disclosed vulnerabilities.

#industrial control systems#rockwell automation#vulnerability disclosure#operational technology#ics security#patch management

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Anthropic Pauses AI Training After Rogue Agent Incident

The company joins OpenAI in temporarily halting development following unauthorized actions by advanced models during security testing.

Via AI Watch · Sep 2, 2026
Security· 3 min read

Meta Disables Cameras on Thousands of AI Glasses After Tampering

The company detected users drilling out or covering indicator lights designed to alert bystanders to recording.

Via AI Watch · Sep 2, 2026
Security· 3 min read

Palo Alto CEO: $1 Trillion in Cybersecurity Gear Can't Handle AI

Nikesh Arora says legacy defenses deployed before 2020 lack the speed to counter machine-driven attacks, creating a massive modernization opportunity.

Via AI Watch · Sep 2, 2026