Rockwell Automation patches 12+ flaws including RSLinx DoS
Rockwell Automation released patches and workarounds for more than a dozen vulnerabilities, including four critical or high-severity denial-of-service flaws in RSLinx Classic.
Rockwell Automation on Tuesday released patches and workarounds for more than a dozen security vulnerabilities across its industrial automation product line. One advisory addresses four critical or high-severity denial-of-service flaws in RSLinx Classic that can crash the RSLinx service and require a restart to recover.
The company identified CVE-2026-9637 as a high-severity DoS issue affecting ControlLogix and CompactLogix controllers. The advisory’s header notes exploitation, while the body lists the issue as not exploited; the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also reported it is not aware of any exploitation.
Rockwell applied additional DoS fixes to the 1756-ENBT communications module, Logix controllers through a third-party component, and FactoryTalk Historian Machine Edition. The vendor also patched a high-severity remote code execution vulnerability in FactoryTalk Historian that could allow an attacker to run arbitrary code on affected systems.
In FactoryTalk Activation Manager, Rockwell resolved a high-severity flaw that permitted an authenticated user to access files, processes and system resources with elevated privileges. The ControlFLASH firmware management utility contains a vulnerability that could allow arbitrary code execution at the logged-in user’s permission level. The Redundancy Module Configuration Tool received a fix for a high-severity privilege escalation issue.
Multiple cross-site scripting vulnerabilities were fixed in ArmorStart Distributed Motor Controllers that could enable execution of malicious scripts, and a denial-of-service issue affecting the controller’s web server was addressed. Several advisories include guidance on applying patches or implementing workarounds to reduce exposure while updates are deployed.
Rockwell issued the notices to customers on Tuesday and provided links to product-specific updates and mitigation steps. CISA posted related advisories the same day to provide additional technical context for operators and security teams.
Rockwell’s advisories recommend prioritizing installation of patches for higher-severity issues and outline mitigations where immediate patching is not possible. The affected products span communications software, programmable logic controllers and management utilities commonly used in manufacturing and critical infrastructure environments.








