We recently relocated all security advisories to this public-facing Security Advisory Portal, which is part of Rockwell Automation’s Trust Center. In the past, our security advisories were stored in the Rockwell Automation Knowledgebase and required authentication to obtain access. This new portal gives customers and partners easier access to advisories, which enables them to better manage the security posture of Rockwell Automation solutions.
The security of our products is important to us as your industrial automation supplier. This security issue was found internally during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
The Redundancy Module Configuration Tool from Rockwell Automation is a software utility used to configure and manage ControlLogix® Redundancy Modules (1756-RM2 and 1756-RM3), supporting setup, diagnostics, and maintenance of redundancy systems in critical industrial environments.
Affected Products and Solution
Affected Software Version
Corrected in Software Version
Affected Catalog Numbers
Redundancy Module Configuration Tool
Redundancy Module Configuration Tool
9.00.00 through 10.00.00
Security Issue Details for CVE-2026-9633
A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.
CWE-276: Incorrect Default Permissions
Known Exploited Vulnerability
Security Issue Details for CVE-2026-9634
A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.
CWE-276: Incorrect Default Permissions
Known Exploited Vulnerability
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices .
· Arbitrary Code Execution: an attacker's ability to run any commands or code of the attacker's choice on a target machine or in a target process
· DLL (Dynamic Link Library): a file containing reusable code and data that can be loaded by Windows applications at runtime to provide shared functionality, reducing redundancy and enabling modular software design.
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. This security issue was responsibly disclosed to us by an external security researcher and is being reported based on our commitment to customer transparency and improvement of all business environments.
FactoryTalk® Activation Manager is a software tool that enables activation and management of Rockwell Automation products without physical media, using internet-based activation files and multiple licensing options.
Affected Products and Solution
Affected Software Version
Corrected in Software Version
Affected Catalog Numbers
FactoryTalk® Activation Manager
Security Issue Details for CVE-2026-16675
A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.
CWE-307: Improper Restriction of Excessive Authentication Attempts
Known Exploited Vulnerability
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices .
· SYSTEM-level privileges: Access or execution rights equivalent to the Windows operating system's highest authority, allowing full control over all processes, files, and configurations.
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. This security issue was found internally during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
FactoryTalk® Historian Machine Edition (ME) is an embedded data historian module for the ControlLogix® chassis that collects, stores, and serves time-series process data directly at the machine level, enabling local data logging and retrieval without requiring a separate server.
Affected Products and Solution
Affected Software Version
Corrected in Software Version
Affected Catalog Numbers
Historian ME (1756-HIST2G Series B & C)
Series C: 7.101 Series B: 5.202
1756-HIST2G/C 1756-HIST2G/B
Historian ME (1756-HIST2G Series B & C)
Series C: 7.101 Series B: 5.202
1756-HIST2G/C 1756-HIST2G/B
Security Issue Details for CVE-2025-12768
A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.
CWE-787: Out-of-bounds Write
Known Exploited Vulnerability
Security Issue Details for CVE-2026-12661
A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
CWE-121: Stack-based Buffer Overflow
Known Exploited Vulnerability
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices .
· Remote Code Execution: allows attackers to run arbitrary code on a remote machine, connecting to it over public or private networks
· Buffer Overflow: when a program writes more data to a buffer than it can hold, causing the excess data to overflow into adjacent memory locations
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. This security issue was found internally during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
Controllers from Rockwell Automation deliver high-speed, multi-discipline control for discrete, motion, process, and safety applications, featuring enhanced security, integrated motion over EtherNet/IP.
Affected Products and Solution
Affected Firmware Version
Corrected in Firmware Version
Affected Catalog Numbers
Compact GuardLogix® 5380
Versions prior to 36.013,
Versions prior to 35.014,
Versions prior to 34.015
Version 37.011 and later,
Version 36.013 and later,
Version 35.014 and later,
Version 34.015 and later
1756-L8z 1756-L8zS 5069-L3z 5069-L3zS 5069-L4
Security Issue Details
A potential denial of service security issue exists in the affected products and can be triggered via corrupt crafted data. This could result in a major non-recoverable fault (MNRF).
A program download is required to recover safety controllers.
For non-safety controllers a stage 2 reset is required to recover see chapter 5 for instructions.
CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
Known Exploited Vulnerability
No (Not listed in KEV database)
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices .
Denial of Service (DoS): Attack is a malicious attempt to disrupt the normal functioning of a targeted server, service, or network by overwhelming it with a flood of traffic or triggering a crash.
Major Non-Recoverable Fault (MNRF): an error that occurs in a system or device and prevents it from recovering or functioning properly.
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. This security issue was reported from an external source during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
The 1756-ENBT module from Rockwell Automation is a ControlLogix® EtherNet/IP bridge that enables communication between Logix 5000® controllers and Ethernet devices
Affected Products and Solution
Affected Firmware Version
Corrected in Firmware Version
Affected Catalog Numbers
Upgrade to 1756-EN2T or
1756-ENBT, 1756-EWEB, L3xX
Security Issue Details
A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.
Known Exploited Vulnerability
No (Not listed in KEV database)
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices .
· Denial of Service (DoS): Attack is a malicious attempt to disrupt the normal functioning of a targeted server, service, or network by overwhelming it with a flood of traffic or triggering a crash.
· CIP Packet : Control and Information Protocol is a media independent protocol used for manufacturing automation
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. This security issue was found internally during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
RSLinx® Classic from Rockwell Automation is a communications software that provides connectivity between Allen‑Bradley devices and Rockwell Automation applications, running as a Windows service to deliver real‑time data access for configuration, programming, and monitoring across industrial automation systems.
Affected Products and Solution
Affected Software Version
Corrected in Software Version
Affected Catalog Numbers
Security Issue Details for CVE-2026-9621
A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
CWE-190: Integer Overflow or Wraparound
Known Exploited Vulnerability
Security Issue Details for CVE-2026-9622
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
CWE-191: Integer Underflow (Wrap or Wraparound)
Known Exploited Vulnerability
Security Issue Details for CVE-2026-9624
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.
CWE-191: Integer Underflow (Wrap or Wraparound)
Known Exploited Vulnerability
Security Issue Details for CVE-2026-9625
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Known Exploited Vulnerability
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices .
· CIP: Common Industrial Protocol (CIP) is a common communication standard that is widely used in industrial automation. Comprises a series of protocols for communication between different devices and systems in automation technology
· CIP Packet: A data structure used in the Common Industrial Protocol (CIP) to encapsulate information for communication between industrial devices, including commands, responses, and associated parameters for control and data exchange
· Denial of Service (DoS): A malicious attempt to disrupt the normal functioning of a targeted server, service, or network by overwhelming it with a flood of traffic or triggering a crash.
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. This security issue was found internally during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
ArmorStart® Distributed Motor Controllers are easy-to-deploy, on-machine motor control solutions that simplify installation and support EtherNet/IP™ networks for industrial automation systems.
Affected Products and Solution
Affected Firmware Version
Corrected in Firmware Version
Affected Catalog Numbers
Bul 290E, 291E & 294E
Bul 290E, 291E & 294E
Security Issue Details for CVE-2026-19471
Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Known Exploited Vulnerability
Security Issue Details for CVE-2026-19472
A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability
CWE-770: Allocation of Resources Without Limits or Throttling
Known Exploited Vulnerability
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices .
· Denial-of-Service (DoS): An attack that disrupts the normal functioning of a system, often by overwhelming it with requests.
· Web Server: A software and hardware system that serves content over the internet using the Hypertext Transfer Protocol (HTTP) or its secure version HTTPS. Its primary role is to store, process, and deliver webpages to users' browsers upon request.
· Stored Cross-Site Scripting (XSS): A vulnerability where malicious scripts are stored on the server and executed in the browser of users who access the affected content.
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. This security issue was found internally during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
ControlFLASH™ from Rockwell Automation is a firmware management utility used to download and update firmware on Allen‑Bradley® programmable controllers, modules, and other industrial automation devices.
Affected Products and Solution
Affected Software Version
Corrected in Software Version
Affected Catalog Numbers
Security Issue Details for CVE-2026-12663
A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
CWE-306: Missing Authentication for Critical Function
Known Exploited Vulnerability
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should implement the following mitigation:
To protect the files, do the following steps to remove the Everyone group:
1. Right-click the C:\Program Files (x86)\ControlFLASH\0001 folder, and then select Properties .
2. In the 0001 Properties dialog, select the Security tab, and then select Edit .
3. In the Permissions for 0001 dialog, in Group or user names , select Everyone , and then select Remove .
If the mitigation above cannot be implemented, we recommend following our security best practices .
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. This security issue was found internally during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
The Logix® Platform of products listed below from Rockwell Automation delivers high-speed, multi-discipline control for discrete, motion, process, and safety applications, featuring enhanced security, integrated motion over EtherNet/IP.
Affected Products and Solution
Affected Firmware Version
Corrected in Firmware Version
Affected Catalog Numbers
V33 and prior, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012
V37.011, 36.013, 35.014, 34.015
V33 and prior, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012
V37.011, 36.013, 35.014, 34.015
V33 and prior, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012
V37.011, 36.013, 35.014, 34.015
Compact GuardLogix 5380
V33 and prior, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012
V37.011, 36.013, 35.014, 34.015
Security Issue Details for CVE-2026-9637
A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Known Exploited Vulnerability
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices .
· CIP Communication: Common Industrial Protocol (CIP) is a common communication standard that is widely used in industrial automation. Comprises a series of protocols for communication between different devices and systems in automation technology.
· Denial-of-Service (DoS): An attack that disrupts the normal functioning of a system, often by overwhelming it with requests.
· Major Nonrecoverable Fault (MNRF): an error that occurs in a system or device and prevents it from recovering or functioning properly.
· Buffer Overflow: when a program writes more data to a buffer than it can hold, causing the excess data to overflow into adjacent memory locations.
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
OTTO® Fleet Manager – Weak Password Hashing Configuration
The security of our products is important to us as your industrial automation supplier. This security issue was found internally during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
OTTO® Fleet Manager is enterprise-scale fleet management software that acts as the system supervisor for a fleet of OTTO® autonomous mobile robots (AMRs), intelligently managing work assignments, charging, parking, and traffic so materials move efficiently with minimal human intervention.
Affected Products and Solution
Affected Software Version
Corrected in Software Version
Affected Part Numbers
(See mitigation below on how to implement)
Security Issue Details for CVE-2026-75112
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.
CWE-916: Use of Password Hash With Insufficient Computational Effort
Known Exploited Vulnerability
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions or apply the mitigations below should use our security best practices .
Instructions To Enable Encrypted System Backup OTTO® Fleet Manager now supports encrypted System Backup as of version 2.36.3. Its use is configurable using a user-chosen passphrase. Support for the creation and restoration of unencrypted backups remains.
If configured, system backups will be encrypted with a passphrase that is set when running the cluster setup. That passphrase will be used to decrypt backups for restoration in OTTO® Fleet Manager. A prompt to enter the passphrase during the restore workflow will be displayed if the to-be-restored backup is encrypted.
See either the single or multi-VM cluster deployment instructions for details on changing the system backup encryption passphrase.
Initial installation : When running through the initial configuration of the OTTO® Fleet Manager cluster, entering a passphrase is required to encrypt the OTTO® Fleet Manager system backup. Confirm the configuration by entering the non-blank passphrase again.
Reconfiguration/upgrade : Changing the passphrase requires executing cluster setup again. When reconfiguring/upgrading, the following options will be displayed for system backup encryption:
If a passphrase was not previously set, the basic passphrase setup screen will be shown from initial installations.
If a passphrase was previously set, an option screen will be displayed with the following:
Keep - Keep the existing passphrase (no change)
Change – Set a new passphrase. Setting a new passphrase will require re-entry of the same passphrase to confirm the configuration.
Clear – Remove passphrase and disable backup encryption.
Bcrypt: A password hashing algorithm designed to securely store passwords by incorporating a salt and an adaptive cost factor, making brute-force attacks computationally expensive.
Password Hashing: The process of converting a plaintext password into a fixed-length, irreversible string using a cryptographic hash function, used to securely store and verify user credentials.
Encryption: The process of converting data into an unreadable format using a cryptographic algorithm and key, ensuring that only authorized parties can access the original information.
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, our support here.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
Rockwell Automation DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF Rockwell Automation HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. Rockwell Automation DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. Rockwell Automation has become aware of threat actor activity targeting internet-exposed PLCs, specifically Rockwell Automation/Allen-Bradley’s MicroLogix™ 1400 & MicroLogix™ 1100 series. Threat actors have reportedly targeted these controllers to remotely tamper with device configurations by changing IP addresses and turning on and setting passwords where no passwords were previously set, resulting in a loss of operator view. This activity is described in the FBI Public Service Announcement (PSA), Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions , issued July 30, 2026.
We are sharing this to guide for customers who are unable to access their MicroLogix™ 1400 & MicroLogix™ 1100 controllers because a password has been set that is not known. Reports indicate that threat actors are enabling password protection on affected controllers where no password had previously been enabled or configured. It explains how to return the controller to a factory default state so that a known good project file can be redownloaded. No CVE is associated with this notice; it is operational recovery guidance and hardening steps rather than a vulnerability disclosure.
We also provide a list of primary risk mitigation steps that asset owners can take to secure and harden their OT deployments. Setting a password alone is not sufficient mitigation and should be combined with additional hardening steps referenced in this document. We provide guidance on how to identify and remove devices from the public internet while recognizing that some OT environments require secure, remote access such as a hardened VPN or other solution.
The MicroLogix™ 1400 and MicroLogix™ 1100 from Rockwell Automation are compact programmable logic controllers (PLCs) designed for a wide range of industrial automation applications. The MicroLogix™ 1400 provides a higher I/O count, faster high-speed counter and pulse-train output capabilities, enhanced networking features, and a backlit LCD panel. Both controllers are programmed and maintained using RSLogix 500® software.
Applicable Products and Solution
Applicable Catalog Numbers
MicroLogix™ 1400 Programmable Controller
Clear user application memory via battery removal, then redownload the project file (see procedure below)
MicroLogix™ 1100 Programmable Controller
Set the controller to Program mode using the built-in LCD, then update firmware using ControlFLASH™ over a DF1 serial connection to clear the user program and password, and redownload the project file (see procedure below)
Recovering Access to the MicroLogix™ 1400 Controller
IMPORTANT: The following procedure erases the controller’s program, data, and network (IP) configuration. Ensure that you have an offline backup of your project (.RSS) file before proceeding, as the program cannot be recovered from the controller after the reset.
1. Power off the controller.
2. Remove the controller battery 1747-BA connection. Information installing the battery may be found in the MicroLogix™ 1400 Programmable Controllers User Manual Publication 1766-UM001.
3. Power on the controller.
4. Observe the controller entering a fault state.
5. Power off the controller.
6. Reconnect the battery.
7. The IP address and program are now erased
8. Set the IP address using the LCD panel on the controller.
9. Download your project file to the controller using RSLogix 500®.
Recovering Access to the MicroLogix™ 1100 Controller
IMPORTANT: ControlFLASH™ over Ethernet is not supported.
1. Place the controller into Program mode using the LCD.
2. Connect the PM02 serial cable to the controller. If the computer does not have a serial port, use a USB-to-serial adapter.
3. Using ControlFLASH™, perform a firmware update over the DF1 serial connection.
4. The firmware update process will clear the user program and any configured controller password, restoring access to the device.
• A current offline backup of the controller project (.RSS) file is required, because the reset erases the program from the controller.
• RSLogix 500® programming software and an appropriate programming cable are required to redownload the project.
Important Hardening Guidance
Setting or changing the controller password following recovery is not sufficient by itself nor the primary mitigation to defend against this activity. After restoring the controller, the following hardening steps are recommended as primary mitigations to strengthen your OT security posture, and reduce the risk of unauthorized activity in the future:
• Do not connect the controller directly to the internet. Remove any public IP address or port-forwarding rule and verify that the device is not reachable externally. Refer to the following resources on how to identify exposed assets and disconnect them from the public internet:
• Rockwell Automation | Advisory on web tools that identify ICS devices and systems connected to the Internet
• CISA | NSA and CISA Recommend Immediate Actions to Reduce Exposure Across Operational Technologies and Control Systems
• CISA | How-to Guide: Stuff Off Shodan
• Devices that require remote access should leverage a VPN or other secure remote access solution rather than direct internet exposure, and ensure that access is restricted to authorized users.
• Minimize network exposure for all control system devices and locate them behind firewalls within an isolated OT/plant network, separated from the business network, as part of a defense-in-depth security architecture.
• Limit controller communication to trusted engineering workstations and known IP addresses using firewall rules or access control lists.
• Set the controller to RUN mode using built-in LCD keypad interface to block unauthorized changes to logic, configuration, and firmware.
• On MicroLogix™ 1400 Series B, apply firmware FRN 21.002 or later and enable Enhanced Password Security.
• Maintain current offline backups of project files and controller configuration so you can recover quickly from a fault, lockout, or unauthorized change.
• Monitor network and controller logs for unexpected connection attempts, mode changes, or download activity, and investigate anomalies promptly.
• Disable HTTP server when not required, see PN641 for additional information.
• Keep controllers and software updated to the latest available firmware and software versions to benefit from the most current security protections.
For additional hardening guidance, customers should follow our security best practices.
Added MicroLogix™ 1100 instruction
Added additional hardening guidance
Clarified that setting the password alone is not the primary mitigation
Added additional resources on identifying and removing exposed assets from public internet.
Added additional hardening guidance for secure remote access.
• RSLogix 500®: The programming and configuration software used to develop, download, and maintain projects on MicroLogix™ and SLC™ 500 controllers.
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the guidance above and how to apply it, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this notice, please PSIRT Email: PSIRT@rockwellautomation,com
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAS BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.
The security of our products is important to us as your industrial automation supplier. This security issue was found internally during routine testing and is being reported based on our commitment to customer transparency and improvement of all business environments.
Studio 5000® is Rockwell Automation's integrated design environment for developing, programming, and managing industrial automation systems using Logix 5000® controllers.
Affected Products and Solution
Affected Software Version
Corrected in Software Version
Affected Catalog Numbers
Studio 5000 Logix Designer®
V36.00, 35.00,35.01, 34.00-34.03, 33.00-33.03, 32.00-32.04 and older
V37.00. 36.01, 35.02, 34.04, 33.04, 32.05
Studio 5000 Logix Designer®
V35.00,34.00,34.01, 33.00,33.02, 32.00-32.04 and older
V36.00, 35.01, 34.02, 33.02,32.05
Studio 5000 Logix Designer®
V35.00, 34.00-34.02, 33.00-33.02, 32.00-32.04 and older
V36.00, 35.01, 34.03, 33.03,32.05
Security Issue Details for CVE-2026-9108
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Known Exploited Vulnerability
Security Issue Details for CVE-2026-9127
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.
CWE-863: Incorrect Authorization
Known Exploited Vulnerability
Security Issue Details for CVE-2026-9128
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the order. If exploited, an attacker could plant a malicious executable in a location within the path, resulting in arbitrary code execution with the same permissions of the user running the application.
CWE-428: Unquoted Path or Element
Known Exploited Vulnerability
Mitigations and Workarounds Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices .
· Directory Traversal: also known as path traversal, is a security vulnerability that allows attackers to access files and directories outside the intended scope of a web application or system.
· Arbitrary Code Execution: an attacker's ability to run any commands or code of the attacker's choice on a target machine or in a target process
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
If you have any questions regarding the security issue(s) above and how to mitigate them, TechConnect for help. More information can be found at Us | Rockwell Automation | US.
If you have any questions regarding this disclosure, please PSIRT Email: [email protected]
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESS...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
