Rockwell Automation Releases New Industrial Security Advisories

Rockwell Automation has notified customers about patches and workarounds for more than a dozen vulnerabilities. The affected products span industrial automation, PLC, communications, and control system environments.

Most vulnerabilities involve denial-of-service conditions, privilege escalation, remote code execution, or malicious script execution. Therefore, operators should review affected assets and apply the recommended remediation steps.

RSLinx Classic Faces Critical Denial-of-Service Vulnerabilities

The most serious advisory concerns RSLinx Classic, Rockwell Automation’s industrial communications software. Four critical and high-severity vulnerabilities could trigger denial-of-service conditions.

An attacker could exploit these flaws to crash the RSLinx Classic service. The affected service then requires a restart before communications can resume.

For industrial automation networks, this condition can interrupt PLC communications and engineering operations. Operators should therefore assess RSLinx Classic installations that support production or maintenance activities.

ControlLogix and CompactLogix Vulnerability Listed as Exploited

Rockwell also disclosed CVE-2026-9637, a high-severity denial-of-service vulnerability affecting ControlLogix and CompactLogix controllers.

Rockwell’s advisory marks the vulnerability as exploited in its header. However, other sections classify it as not exploited. CISA also states that it has no evidence of exploitation.

This inconsistency deserves attention from security teams. Until Rockwell clarifies the classification, organizations should treat the vulnerability with appropriate caution and prioritize available mitigations.

Additional DoS Issues Affect Industrial Automation Systems

Rockwell addressed additional denial-of-service vulnerabilities across several products. These include the 1756-ENBT module, Logix controllers, and FactoryTalk Historian Machine Edition.

Some issues involve third-party components integrated into Logix controller environments. Consequently, asset owners should review both Rockwell advisories and applicable component-level security guidance.

In practical deployments, denial-of-service vulnerabilities can affect controller availability without directly modifying the control logic. Nevertheless, unexpected communications failures can disrupt production and maintenance activities.

FactoryTalk Historian Includes a Remote Code Execution Risk

FactoryTalk Historian Machine Edition also contained a high-severity remote code execution vulnerability. Successful exploitation could give an attacker the ability to execute code on an affected system.

Remote code execution presents a broader risk than a simple service interruption. Attackers may potentially use the compromised host as a foothold for further movement across an industrial network.

For this reason, historians and other supervisory systems should receive the same security attention as PLC infrastructure.

FactoryTalk Activation Manager Has a Privilege Escalation Flaw

Rockwell also fixed a high-severity vulnerability in FactoryTalk Activation Manager. An authenticated attacker could potentially access files, processes, and system resources with elevated privileges.

Privilege escalation can increase the impact of an existing compromise. Therefore, organizations should combine software patching with strong account management and least-privilege controls.

Industrial automation environments often contain engineering workstations with broad access. Protecting these systems can reduce the potential impact of compromised user credentials.

ArmorStart Controllers Receive Multiple Security Fixes

Several cross-site scripting vulnerabilities affected ArmorStart Distributed Motor Controllers. These flaws could allow malicious scripts to execute within the affected web interface.

Rockwell also addressed a denial-of-service vulnerability involving the product’s web server. These issues demonstrate why embedded web interfaces require security controls similar to conventional IT applications.

Network segmentation can further reduce exposure. In particular, control-device web interfaces should not remain broadly accessible from corporate or external networks.

ControlFLASH Utility Contains an Arbitrary Code Execution Risk

The ControlFLASH firmware management utility also received a security update. Its vulnerability could allow arbitrary code execution under the permissions of the logged-in user.

ControlFLASH plays an important role in maintaining Rockwell controller firmware. Consequently, compromise of the engineering workstation running this utility could affect maintenance operations.

Organizations should therefore patch engineering tools alongside PLC firmware and controller infrastructure. Updating only field devices may leave the supporting engineering environment exposed.

Redundancy Module Configuration Tool Requires Attention

Rockwell identified a high-severity privilege escalation vulnerability in its Redundancy Module Configuration Tool.

Configuration utilities often operate with elevated system permissions. As a result, attackers may gain broader access if they successfully exploit weaknesses in these applications.

Security teams should inventory engineering software, configuration utilities, and maintenance tools alongside PLC and DCS assets.

What These Vulnerabilities Mean for Industrial Automation

These disclosures highlight a continuing trend in industrial cybersecurity. Modern PLC and factory automation systems increasingly depend on Windows applications, web interfaces, Ethernet communications, and third-party software components.

That architecture expands the potential attack surface around traditional control systems. Therefore, cybersecurity programs should protect engineering workstations, communication servers, historians, and configuration utilities.

From an industrial operations perspective, availability remains a major concern. A vulnerability does not need to manipulate a PLC program to disrupt production.

Recommended Security Actions for PLC and Control Systems

Industrial operators should first identify affected Rockwell products across their automation environment. Next, teams should compare installed versions against Rockwell’s current security advisories.

Where patches are available, organizations should test updates before deployment in production environments. However, critical infrastructure may require controlled maintenance windows and rollback planning.

Security teams should also consider network segmentation, restricted remote access, account management, application allowlisting, and continuous asset monitoring.

For ControlLogix and CompactLogix environments, engineers should additionally verify controller firmware, communication modules, engineering software, and associated FactoryTalk components.

Practical Factory Automation Security Scenario

Consider a manufacturing plant using ControlLogix PLCs, RSLinx Classic, FactoryTalk Historian, and engineering workstations.

An attacker could target an exposed engineering application rather than the PLC directly. A successful compromise could then disrupt communications, access system resources, or establish a path toward other network assets.

A layered defense therefore provides better protection than relying on PLC security alone. Operators should combine patch management with segmentation and controlled engineering access.

Expert View: Patch Management Must Include Engineering Software

In my experience with industrial automation systems, maintenance teams often prioritize PLC firmware and overlook engineering applications.

That approach creates unnecessary exposure because engineering workstations frequently interact with many controllers. They may also contain configuration files, diagnostic tools, firmware utilities, and privileged credentials.

Rockwell’s latest disclosures reinforce this point. Industrial cybersecurity programs should treat engineering software as part of the control-system security boundary.

Moreover, organizations should track vulnerabilities by asset function, not only by product name. A historian, engineering workstation, communications server, and PLC can create different operational risks.

Rockwell Security Advisories and CISA Guidance

Rockwell Automation provides product-specific security advisories covering affected versions, remediation options, and available workarounds.

CISA’s Industrial Control Systems advisories provide an additional reference for organizations managing operational technology environments. Operators should compare vendor guidance with their own asset inventories before making production changes.

Because vulnerability status can change, security teams should verify the latest advisory information before deployment or risk acceptance.

Conclusion

Rockwell Automation’s latest security disclosures affect multiple layers of the industrial automation stack. The issues range from denial-of-service vulnerabilities to remote code execution and privilege escalation.

The findings reinforce a practical cybersecurity lesson: PLC protection alone is not enough. Engineering software, communications infrastructure, historians, and configuration tools also require continuous security management.

For manufacturers operating Rockwell control systems, timely asset identification and controlled patch deployment should remain core parts of the industrial cybersecurity program.