CVE Tools

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

SecurityWeekBy Eduard Kovacs

PatchRSLinx ClassicControlLogix

Our summary

Rockwell Automation has issued patches and workarounds for over a dozen vulnerabilities spanning several of its industrial automation platforms. The updates address high-severity denial-of-service issues in RSLinx Classic and ControlLogix, as well as remote code execution flaws in FactoryTalk Historian and arbitrary code execution risks in the ControlFLASH firmware management utility.

Additional fixes resolve cross-site scripting attacks in ArmorStart Distributed Motor Controllers and privilege escalation vulnerabilities in both FactoryTalk Activation Manager and the Redundancy Module Configuration Tool. While an initial advisory flagged CVE-2026-9637 as exploited, CISA and subsequent documentation confirm there is no evidence of active exploitation.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store