Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
Rockwell Automation disclosed patches or workarounds for over a dozen vulnerabilities across its industrial automation product line Four critical/high-severity DoS vulnerabilities in RSLinx Classic communications software are the only critical findings, causing service crashes requiring restart A high-severity remote code execution flaw was fixed in FactoryTalk Historian, and an authenticated privilege escalation vulnerability was resolved in FactoryTalk Activation Manager Multiple XSS vulnerabi
Analysis
TL;DR
- Rockwell Automation disclosed patches or workarounds for over a dozen vulnerabilities across its industrial automation product line
- Four critical/high-severity DoS vulnerabilities in RSLinx Classic communications software are the only critical findings, causing service crashes requiring restart
- A high-severity remote code execution flaw was fixed in FactoryTalk Historian, and an authenticated privilege escalation vulnerability was resolved in FactoryTalk Activation Manager
- Multiple XSS vulnerabilities and a DoS issue were patched in ArmorStart Distributed Motor Controllers
- ControlFLASH firmware management utility and Redundancy Module Configuration Tool were found vulnerable to arbitrary code execution and privilege escalation, respectively
Why It Matters
This is significant for industrial cybersecurity practitioners because Rockwell Automation products form the backbone of many critical manufacturing and infrastructure systems in North America. The disclosure of remote code execution and privilege escalation flaws in widely deployed industrial software underscores the ongoing attack surface expansion in OT environments, where patching cycles are typically slower than in IT. The CISA co-publication signals heightened government attention to industrial control system vulnerabilities.
Technical Details
- RSLinx Classic: Four critical/high-severity DoS vulnerabilities (CVE-2026-9637 series) that crash the service upon exploitation; patches or workarounds are available
- ControlLogix and CompactLogix controllers: CVE-2026-9637, a high-severity DoS flaw; Rockwell initially flagged it as exploited but CISA advisory states no known exploitation; likely a documentation error
- FactoryTalk Historian Machine Edition: High-severity remote code execution vulnerability patched
- FactoryTalk Activation Manager: High-severity authenticated privilege escalation flaw allowing access to files, processes, and system resources with elevated privileges
- ArmorStart Distributed Motor Controllers: Multiple cross-site scripting (XSS) vulnerabilities enabling malicious script execution, plus a DoS issue affecting the web server
- ControlFLASH firmware management utility: Vulnerability allowing arbitrary code execution at the logged-in user's permission level
- Redundancy Module Configuration Tool: High-severity privilege escalation flaw
- 1756-ENBT and Logix controllers (third-party component): DoS vulnerabilities addressed
Industry Insight
- Organizations running Rockwell Automation infrastructure should prioritize patching RSLinx Classic and FactoryTalk Historian immediately, as these represent the highest-severity exposure with potential for service disruption and remote code execution
- The discrepancy between Rockwell's and CISA's exploitation status for CVE-2026-9637 highlights the importance of cross-referencing vendor advisories with government cybersecurity bulletins before assuming threat posture
- The concentration of flaws in configuration and firmware management tools (ControlFLASH, Redundancy Module Configuration Tool) suggests that supply chain and maintenance interfaces remain an underappreciated attack vector in OT environments, warranting stricter access controls and network segmentation
Disclaimer: The above content is generated by AI and is for reference only.