Rockwell Automation has issued patches and workarounds for more than a dozen vulnerabilities across its industrial automation products, including critical and high-severity flaws in RSLinx Classic, ControlLogix, CompactLogix, and other tools. The advisories cover denial-of-service, remote code execution, privilege escalation, and cross-site scripting issues, with CISA also publishing guidance for CVE-2026-9637. #RockwellAutomation #RSLinxClassic #ControlLogix #CompactLogix #FactoryTalkHistorian #FactoryTalkActivationManager #ControlFLASH
Keypoints
- Rockwell Automation released fixes and workarounds for over a dozen product vulnerabilities.
- RSLinx Classic is affected by four critical and high-severity DoS issues that can crash the service.
- CVE-2026-9637 in ControlLogix and CompactLogix is listed as high severity, though exploitation status appears inconsistent.
- FactoryTalk Historian and ControlFLASH have vulnerabilities that could enable remote code execution.
- ArmorStart, FactoryTalk Activation Manager, and the Redundancy Module Configuration Tool also received security fixes.