#RSLinx
Everyday at work
November 16, 2025 at 6:40 PM
Rockwell Automation、ICSコントローラーおよびソフトウェアの脆弱性にパッチを適用

Rockwell Automationは火曜日、Logix/CompactLogixコントローラー、Flex I/Oデュアルポート Ethernet/IPアダプター、RSLinx産業用通信ソフトウェ
Rockwell Automation、ICSコントローラーおよびソフトウェアの脆弱性にパッチを適用
Rockwell Automationは火曜日、Logix/CompactLogixコントローラー、Flex I/Oデュアルポート Ethernet/IPアダプター、RSLinx産業用通信ソフトウェ
blackhatnews.tokyo
June 17, 2026 at 11:37 AM
"The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products." www.securityweek.com/rockwell-aut...
Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software
Rockwell Automation informed customers that patches are available for several vulnerabilities affecting its ICS controllers and software.
www.securityweek.com
June 19, 2026 at 5:26 PM
ロックウェル・オートメーション、RSLinx・Logix・FactoryTalkにわたる十数件の脆弱性を修正

ロックウェル・オートメーションは、産業施設で使用されているソフトウェアおよびコントローラーに存在していた十数件の脆弱性を修正しました。最も深刻な欠陥では、制御システムのコンポーネントを停止させたり、デバイス上でコードを実行したり、Windowsで SYSTEM権限を取得したりすることが可能でした。...
ロックウェル・オートメーション、RSLinx・Logix・FactoryTalkにわたる十数件の脆弱性を修正
ロックウェル・オートメーションは、産業施設で使用されているソフトウェアおよびコントローラーに存在していた十数件の脆弱性を修正しました。最も深刻な欠陥では、制御システムのコンポーネントを停止させたり、デバイス上でコードを実行したり、Windowsで SYSTEM権限を取得したりすることが可能でした。
blackhatnews.tokyo
September 7, 2026 at 2:16 PM
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products www.securityweek.com/rockwell-aut...
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.
www.securityweek.com
September 3, 2026 at 6:12 PM
Rockwell Automation released patches and workarounds for 12+ vulnerabilities across industrial products, including critical flaws in RSLinx Classic, ControlLogix, and CompactLogix, covering DoS, RCE, privilege escalation, and XSS. #RockwellAutomation
Rockwell Automation Patches Over A Dozen Vulnerabilities Across Products
Rockwell Automation has issued patches and workarounds for more than a dozen vulnerabilities across its industrial automation products, including critical and high-severity flaws in RSLinx Classic, ControlLogix, CompactLogix, and other tools. The advisories cover denial-of-service, remote code execution, privilege escalation, and cross-site scripting issues, with CISA also publishing guidance for CVE-2026-9637....
www.hendryadrian.com
September 2, 2026 at 5:00 PM
Patches and workarounds are available for over a dozen vulnerabilities across Rockwell Automation industrial automation products, including critical DoS issues in RSLinx Classic.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 2, 2026 at 12:53 PM
Patches and workarounds are available for over a dozen vulnerabilities across Rockwell Automation industrial automation products, including critical DoS issues in RSLinx Classic.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 2, 2026 at 12:53 PM
Patches and workarounds are available for over a dozen vulnerabilities across Rockwell Automation industrial automation products, including critical DoS issues in RSLinx Classic.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 2, 2026 at 12:53 PM
Rockwell Automationは、RSLinx Classic等に多数の脆弱性を修正。攻撃者による情報漏洩やシステム操作の可能性。
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
Rockwell Automation has patched more than a dozen vulnerabilities across several of its industrial automation products.
www.securityweek.com
September 2, 2026 at 4:35 PM
~Cisa~
Crafted CIP packets can crash RSLinx Classic <=4.50; upgrade to 4.60.
-
IOCs: CVE-2026-9621, CVE-2026-9622, CVE-2026-9624
-
#CVE2026 #ICS #ThreatIntel
RSLinx Classic DoS Flaws
www.cisa.gov
September 1, 2026 at 8:12 PM
CVE-2026-9621 - rslinx classic®
The RSLinx Classic software that connects your control devices can stop working if it receives a specially formed network packet. This causes the service to…

Too many irrelevant or confusing CVEs? Use stackflag.com

#rslinxclassic #rockwellautomation #CVE #infosec
CVE-2026-9621: RSLinx Classic can crash from malformed network packets
The RSLinx Classic software that connects your control devices can stop working if it receives a specially formed network packet.
stackflag.com
September 1, 2026 at 4:30 PM
Latest post from CISA
Rockwell Automation RSLinx Classic
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) CVSS Vendor Equipment Vulnerabilities v3 8.6 Rockwell Automation Rockwell Automation RSLinx Classic Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9621 A denial-of-service security issue exists within RSLinx Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx Classic service to crash, requiring a restart of the service to recover. View CVE Details Affected Products Rockwell Automation RSLinx Classic Vendor: Rockwell Automation Product Version: Rockwell Automation RSLinx Classic: <=4.50 Product Status: known_affected Remediations Vendor fix Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60. Mitigation Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight. https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html Relevant CWE: CWE-190 Integer Overflow or Wraparound Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.6 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H 4.0 9.2 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H CVE-2026-9622 A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx Classic service to crash, requiring a restart of the service to recover. View CVE Details Affected Products Rockwell Automation RSLinx Classic Vendor: Rockwell Automation Product Version: Rockwell Automation RSLinx Classic: <=4.50 Product Status: known_affected Remediations Vendor fix Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60. Mitigation Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight. https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html Relevant CWE: CWE-191 Integer Underflow (Wrap or Wraparound) Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.6 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H 4.0 9.2 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H CVE-2026-9624 A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet can cause the RSLinx Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover. View CVE Details Affected Products Rockwell Automation RSLinx Classic Vendor: Rockwell Automation Product Version: Rockwell Automation RSLinx Classic: <=4.50 Product Status: known_affected Remediations Vendor fix Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60. Mitigation Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight. https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html Relevant CWE: CWE-191 Integer Underflow (Wrap or Wraparound) Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-9625 A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx Classic service to crash, requiring a restart of the service to recover. View CVE Details Affected Products Rockwell Automation RSLinx Classic Vendor: Rockwell Automation Product Version: Rockwell Automation RSLinx Classic: <=4.50 Product Status: known_affected Remediations Vendor fix Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60. Mitigation Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight. https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Rockwell Automation reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-01 Date Revision Summary 2026-09-01 1 Initial Republication of Rockwell Automation Advisory Legal Notice and Terms of Use
www.cisa.gov
September 1, 2026 at 3:49 PM
ロックウェル・オートメーション、複数製品にまたがる10件超の脆弱性を修正

ロックウェル・オートメーションは火曜日、産業オートメーション製品群で発見された10件を超える脆弱性について、パッチまたは回避策が利用可能になったと顧客に通知しました。 新たに公開されたアドバイザリのうち、深刻度が「クリティカル」とされているのは1件のみです。これはRSLinx Classic通信ソフトウェアに影響する
ロックウェル・オートメーション、複数製品にまたがる10件超の脆弱性を修正
ロックウェル・オートメーションは火曜日、産業オートメーション製品群で発見された10件を超える脆弱性について、パッチまたは回避策が利用可能になったと顧客に通知しました。 新たに公開されたアドバイザリのうち、深刻度が「クリティカル」とされているのは1件のみです。これはRSLinx Classic通信ソフトウェアに影響する
blackhatnews.tokyo
September 2, 2026 at 1:01 PM
🚨 CVE-2026-9621 — CVSS 9.2 CRITICAL

A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper ha...

🔎 https://stemshop.top/cve/CVE-2026-9621

#CVE #CyberSecurity #InfoSec
September 1, 2026 at 4:08 PM
Win11 26H2 build 26300.9278 is in Release Preview, not GA. Patch FactoryTalk Historian for CVE-2025-12768 RCE; RSLinx 4.50 has unpatched CIP DoS. Intune OS-build filters are GA. Explorer menus move custom commands. +11 more stories, 64 new members
Windows 11 26H2 Release Preview: Should You Join?
Windows 11 version 26H2 has entered the Release Preview Channel, but that does not make it generally available—or automatically suitable for every PC. Microsoft released build 26300.9278 to Release…
windowsforum.com
September 1, 2026 at 6:00 PM
Rockwell Automation has patched multiple ICS vulnerabilities in Logix, CompactLogix, Flex I/O, RSLinx, and FactoryTalk, including auth bypass, privilege escalation, and DoS flaws. #RockwellAutomation #FactoryTalk #ICS
Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software
Rockwell Automation has released patches for multiple vulnerabilities affecting Logix and CompactLogix controllers, Flex I/O dual-port Ethernet/IP adapters, RSLinx, and the FactoryTalk suite. The issues include authentication bypass, privilege escalation, password changes through unauthorized access, and denial-of-service flaws, while the company says none of the newly patched bugs have been exploited...
www.hendryadrian.com
June 17, 2026 at 1:45 PM
Rockwell Automation Patches Critical Industrial Control System Vulnerabilities Across Factory Platforms + Video

A New Security Warning for the Industrial World Industrial environments are facing another reminder that cybersecurity is no longer limited to traditional computers and corporate…
Rockwell Automation Patches Critical Industrial Control System Vulnerabilities Across Factory Platforms + Video
A New Security Warning for the Industrial World Industrial environments are facing another reminder that cybersecurity is no longer limited to traditional computers and corporate networks. Rockwell Automation has released security updates addressing multiple vulnerabilities affecting widely used industrial control system (ICS) products, including Logix controllers, CompactLogix, Flex I/O, RSLinx, and FactoryTalk platforms. The vulnerabilities reportedly include authentication bypass issues, privilege escalation weaknesses, and denial-of-service flaws that could impact industrial operations if exploited.
undercodenews.com
June 17, 2026 at 3:24 PM
5,219 Exposed Rockwell PLCs Under Active Attack: Iranian APT’s OT-LOLBins Campaign + Video

Introduction: Iranian state-sponsored actors (IRGC Cyber Electronic Command, tracked as CyberAv3ngers/UNC5691) are actively exploiting internet‑exposed Rockwell Automation/Allen‑Bradley PLCs without needing…
5,219 Exposed Rockwell PLCs Under Active Attack: Iranian APT’s OT-LOLBins Campaign + Video
Introduction: Iranian state-sponsored actors (IRGC Cyber Electronic Command, tracked as CyberAv3ngers/UNC5691) are actively exploiting internet‑exposed Rockwell Automation/Allen‑Bradley PLCs without needing zero‑day vulnerabilities. By abusing legitimate engineering tools such as Studio 5000 and RSLinx, attackers manipulate industrial processes directly—a classic “living‑off‑the‑land” technique adapted for OT environments (OT‑LOLBins). With over 5,200 exposed devices globally, nearly 75% in the U.S., this campaign poses an immediate risk to water, energy, and government facilities.
undercodetesting.com
April 13, 2026 at 3:07 PM
Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products. ...

#ICS/OT #Vulnerabilities #ICS #Rockwell #Automation #vulnerability

Origin | Interest | Match
Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software
event.on24.com
June 17, 2026 at 2:26 PM
Rockwell Automation RSLinx View CSAF Summary Successful exploitation of this vulnerability can lead to a denial of service, where the application will become unresponsive and will not recover on it...

Origin | Interest | Match
Rockwell Automation RSLinx | CISA
www.cisa.gov
June 16, 2026 at 4:57 PM
Rockwell Automation RSLinx View CSAF Summary Successful exploitation of this vulnerability can lead to a denial of service, where the application will become unresponsive and will not recover on it...

Origin | Interest | Match
Rockwell Automation RSLinx | CISA
www.cisa.gov
June 16, 2026 at 4:56 PM