CISA republished multiple Rockwell Automation advisories covering vulnerabilities across FactoryTalk Analytics PavilionX, RSLinx Classic, CompactLogix 5370, Logix 5370/5570 controllers, and FLEX I/O EtherNet/IP Adapters used in critical manufacturing environments worldwide. The issues include an authorization bypass in PavilionX (CVE-2025-14272) that could let an unauthenticated attacker perform privileged administrative actions, and a third-party flaw in RSLinx Classic (CVE-2020-13573) tied to out-of-bounds read and stack-based buffer overflow conditions that could cause denial of service or enable remote arbitrary code execution.
Additional advisories detail multiple CIP-related denial-of-service weaknesses in CompactLogix and Logix controllers, including CVE-2026-11317, where crafted CIP messages can trigger major nonrecoverable faults requiring a program download, as well as sequence-number, source-IP, and connection-ID issues that can induce controller faults. CISA also warned that FLEX I/O EtherNet/IP Adapters version 2.012 are affected by CVE-2026-0646, which can fault devices through malformed CIP requests, and CVE-2026-0647, a critical authentication bypass in the embedded web server that allows password changes through a crafted HTTP GET request, potentially leading to account takeover and loss of availability; CISA said no known public exploitation had been reported and urged operators to isolate control networks, reduce internet exposure, and secure remote access with firewalls and updated VPNs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Rockwell Automation released patches for vulnerabilities affecting FactoryTalk Historian. SecurityWeek reported that CISA distributed Rockwell advisories for other products on June 16, 2026, but did not publish an advisory for the FactoryTalk Historian issues.
Rockwell Automation published security advisory SD1777 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.
Rockwell Automation published security advisory SD1776 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.
Rockwell Automation published security advisory SD1775 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.
Rockwell Automation published security advisory SD1774 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.
Rockwell Automation published security advisory SD1773 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.
Rockwell Automation published security advisory SD1772 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.
On 2026-06-16, CISA republished a Rockwell Automation advisory covering CVE-2026-0646 and CVE-2026-0647 in FLEX I/O EtherNet/IP Adapters 1794-AENTR and 1794-AENTRXT version 2.012. The vulnerabilities include a denial-of-service condition and a critical authentication bypass in the embedded web server that can let an unauthenticated attacker change the web interface password.
On 2026-06-16, CISA republished a Rockwell Automation advisory describing two vulnerabilities in CompactLogix 5370 L1, L2, and L3 controllers earlier than V38.011. The issues involve improper validation in the CIP protocol and exposure of CIP Connection IDs through the web interface, enabling denial-of-service conditions that cause a minor fault.
On 2026-06-16, CISA republished a Rockwell Automation advisory for CVE-2026-11317 affecting multiple Logix 5370 and 5570 controller families. The flaw can be triggered with a crafted CIP message to cause a major nonrecoverable fault, and CISA said no known public exploitation had been reported at the time of publication.
On 2026-06-16, CISA republished a Rockwell Automation advisory for RSLinx Classic 4.50.00 and earlier covering CVE-2020-13573. The advisory said exploitation could cause denial of service and also described a stack-based buffer overflow that could allow remote arbitrary code execution; no known public exploitation was reported to CISA at publication time.
On 2026-06-16, CISA republished a Rockwell Automation advisory describing CVE-2025-14272, a missing-authorization flaw in FactoryTalk Analytics PavilionX versions earlier than 7.01 that could let an unauthenticated attacker perform privileged administrative actions. CISA said no known public exploitation specifically targeting the issue had been reported at the time of publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityweek.com
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcerockwellautomation.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.