Rockwell Automation released patches and mitigations for more than a dozen vulnerabilities affecting industrial-control hardware and software, including RSLinx Classic, CompactLogix and ControlLogix controllers, ArmorStart LT, FactoryTalk products, ControlFLASH, and the Redundancy Module Configuration Tool. Five flaws are rated high severity, while four critical/high-severity RSLinx Classic denial-of-service vulnerabilities can crash the service and require a restart; other issues could enable remote or arbitrary code execution, privilege escalation, cross-site scripting, and denial-of-service attacks.
The Canadian Centre for Cyber Security urged administrators to review Rockwell advisories SD1792, SD1794, SD1797, and SD1798 and apply available firmware and software updates. Organizations unable to patch should reduce exposure in line with vendor guidance. A ControlLogix/CompactLogix denial-of-service advisory header identifies CVE-2026-9637 as exploited, but the advisory body and CISA’s corresponding notice state that known exploitation has not been observed.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-869 warning of vulnerabilities affecting multiple Rockwell Automation products, including 1756-ENBT modules, ArmorStart LT, CompactLogix 5380, ControlLogix 5580, and RSLinx Classic. It directed administrators to review Rockwell advisories SD1792, SD1794, SD1797, and SD1798 and apply available updates.
Rockwell's advisory header for the high-severity ControlLogix and CompactLogix denial-of-service flaw CVE-2026-9637 labeled it exploited, while the advisory body said it was not exploited. CISA's corresponding advisory also said it was not aware of exploitation.
Rockwell Automation announced patches or workarounds for more than a dozen vulnerabilities across products including RSLinx Classic, Logix controllers, FactoryTalk software, ArmorStart, ControlFLASH, and the Redundancy Module Configuration Tool. The fixes addressed denial-of-service, remote and arbitrary code execution, privilege escalation, and cross-site-scripting flaws.
Italy's ACN reported newly identified vulnerabilities in Rockwell Automation products, including five rated high severity, that could enable denial-of-service, remote-code-execution, and elevation-of-privilege attacks. The notice listed CompactLogix, ControlLogix, GuardLogix, FactoryTalk Activation Manager, Historian ME, and the Redundancy Module Configuration Tool, and recommended updates or exposure-reduction measures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceacn.gov.it
Open sourcetenable.com
Open sourcetenable.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.