AI analysis
CVE-2026-9637 is a high-severity denial-of-service vulnerability in Rockwell Automation's Logix controller platform, caused by improper validation of input length during CIP (Common Industrial Protocol) message processing. An attacker who can send crafted CIP messages to an affected controller over the network can trigger the flaw without needing credentials or user interaction. Successful exploitation produces a major nonrecoverable fault (MNRF) that halts the controller and requires a physical power cycle to restore operation, making this an availability-only issue per the CVSS vector. Any site running an affected Logix controller is exposed, with the greatest risk to controllers reachable from untrusted networks such as IT/OT boundary links, VPNs, or internet-exposed EtherNet/IP interfaces. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Review Rockwell Automation's security advisory for CVE-2026-9637 to determine whether your controller models and firmware are affected, and upgrade to the fixed firmware versions it specifies. Until patching, restrict network access to affected controllers by firewalling EtherNet/IP traffic (TCP/UDP 44818 and UDP 2222) to trusted hosts and removing any direct internet exposure. Because recovery requires a physical power cycle, plan maintenance windows and ensure controller logic backups are current before remediating.
Affected
| Rockwell Automation Logix platform controllers (the advisory references a table of affected platforms; individual models are not enumerated | Affected model/firmware ranges per the Rockwell Automation security advisory; no specific version numbers provided in the source data |
Estimated exposure
mass≈1M+ installed Logix controllers across affected platforms, with on the order of tens of thousands reachable from untrusted networks — Rockwell is the largest industrial controller vendor in North America with a Logix-family installed base in the millions, while public internet scans of EtherNet/IP (TCP/44818) typically show tens of thousands of exposed controllers; the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover