ThreatCluster

Denial-of-Service Vulnerabilities in Rockwell Automation Logix Platforms

First seen 1 Sep 2026, 17:00 UTC Cisa 58

Article Content

Browse articles
ThreatCluster

On September 1, 2026, CISA published advisories regarding denial-of-service vulnerabilities in Rockwell Automation's Logix platforms, specifically affecting ControlLogix and CompactLogix systems. The vulnerabilities, identified as CVE-2026-9637 and CVE-2021-42260, can be triggered by corrupt crafted data or improper input length validation during message processing. Affected versions include ControlLogix 5580 and CompactLogix 5380 with firmware versions below 34.015 and 35.014, respectively. The vulnerabilities could lead to major nonrecoverable faults (MNRF), necessitating either a program download or a power cycle for recovery. Rockwell Automation recommends users upgrade to the latest firmware versions to mitigate the risks. CISA advises implementing security best practices to minimize network exposure and enhance system security. The vulnerabilities are applicable worldwide and impact critical manufacturing sectors.

Key Points: • CVE-2026-9637 and CVE-2021-42260 affect multiple Rockwell Automation Logix platforms. • Denial-of-service vulnerabilities can cause major nonrecoverable faults (MNRF). • Users are urged to upgrade firmware to versions 34.015 and later for mitigation.

Timeline

2021-10-11
CVE-2021-42260 published
Denial-of-service vulnerability disclosed affecting Rockwell Automation products.
Cisa
2026-09-01
CVE-2026-9637 published
New denial-of-service vulnerability disclosed for Rockwell Automation Logix platforms.
Cisa
2026-09-01
CISA advisory issued
CISA warns of vulnerabilities in Rockwell Automation systems and recommends firmware upgrades.
Cisa