CISA warns CVE-2026-77477 (CVSS 4.6) lets local attackers hijack a privileged console during OPC UA LDS installation below version 1.04.420.
CISA published ICSA-26-246-01 for CVE-2026-77477, CWE-250 execution with unnecessary privileges in OPC Foundation UA-LDS-Installers below 1.04.420. An attacker able to launch the installer with elevated privileges and access the keyboard and display can intercept a high-privilege console window during installation and run arbitrary commands. CVSS 3.1 score is 4.6, the issue is not remotely exploitable, and no public exploitation has been reported. Lukas Schumaker of Rockwell Automation reported the flaw to OPC Foundation.
CISA warns CVE-2026-9633 in Rockwell Automation Redundancy Module Configuration Tool lets attackers execute processes with administrator privileges; fix in 10.01.00.
CISA released an ICS advisory for Rockwell Automation Redundancy Module Configuration Tool. CVE-2026-9633 could allow an attacker to escalate privileges and execute processes with administrator rights. Versions 9.00.00 through 10.00.00 are affected, and the vendor shipped a fix in version 10.01.00.
CISA warns CVE-2025-12768 and CVE-2026-12661 in Rockwell Historian ME could crash devices or allow remote code execution via out-of-bounds writes; CVSS 8.
CISA issued an ICS advisory for Rockwell Automation Historian ME Series B 5.202 and Series C 7.101. CVE-2025-12768 and CVE-2026-12661 involve out-of-bounds write and stack-based buffer overflow flaws that could crash the accessed device or enable remote code execution. The product is deployed across chemical, critical manufacturing, healthcare, and water and wastewater sectors worldwide.
CISA details CVE-2026-16675, a CVSS 7.8 privilege escalation flaw in Rockwell FactoryTalk Activation Manager V5.02 and below, with vendor fixes available.
CISA issued an ICS advisory for Rockwell Automation FactoryTalk Activation Manager. CVE-2026-16675 is a privilege escalation vulnerability stemming from installer custom actions, scored 7.8. Versions V5.02 and below are affected, and Rockwell Automation has released fixes.
CISA advisory maps CVE-2021-42260 to Rockwell ControlLogix, CompactLogix, and GuardLogix controllers with firmware below per-series patch levels.
CISA published an ICS advisory associating CVE-2021-42260 with multiple Rockwell Automation controller families: ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, CompactLogix 5480, and Compact GuardLogix 5380. Affected firmware versions fall below 34.015, 35.014, 36.013, and 37.011 depending on the series. The vendor provides updated firmware as remediation.
CISA flags four flaws (CVE-2026-9621/9622/9624/9625) in Rockwell RSLinx Classic 4.50 and below that can cause denial-of-service conditions; CVSS 8.6.
CISA published an ICS advisory covering four vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and below. The integer overflow, underflow, and classic buffer overflow flaws (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) could let attackers cause denial-of-service conditions. The product is deployed worldwide, primarily in critical manufacturing.
Unauthenticated Remote DoS in Rockwell Automation RSLinx Classic
CVE-2026-9621 is a critical-severity (CVSS 4.0: 9.2) denial-of-service flaw in Rockwell Automation's RSLinx Classic, caused by improper handling of malformed packets and classified under CWE-190 (integer overflow/wraparound). A remote, unauthenticated attacker can trigger the condition by sending a specially crafted CIP packet to the service over the network. The impact is availability-only: the RSLinx Classic service crashes and must be manually restarted to recover, with no confidentiality or integrity impact per the CVSS vector, though the high subsequent-system (SA:H) score indicates downstream OT systems and processes can be disrupted. Any installation running the RSLinx Classic service where the CIP endpoint is network-reachable is affected, most typically plant-floor or engineering workstations. There is no public proof-of-concept, no CISA KEV listing, and EPSS is low (0.3%), so active exploitation is currently considered unlikely or unobserved.
Unauthenticated Denial-of-Service in Rockwell Automation RSLinx Classic
CVE-2026-9622 is a remotely exploitable denial-of-service flaw in Rockwell Automation RSLinx Classic, an industrial communications and OPC server product used alongside Allen-Bradley controllers. An attacker with network reachability to the service can send a crafted CIP (Common Industrial Protocol) packet targeting the Forward Close service, which the software mishandles due to an integer coercion error (CWE-191). The result is a crash of the RSLinx Classic service, and a manual restart of the service is required to restore operations; there is no confidentiality or integrity impact and no indication of code execution. The CVSS 4.0 score of 8.7 (High) reflects unauthenticated network access with a high availability impact on the vulnerable system. No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates the 30-day exploitation probability at about 0.3 percent, so no exploitation is currently known.
Denial-of-Service in Rockwell Automation RSLinx Classic via Oversized CIP Packet
CVE-2026-9625 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software, caused by improper handling of input sizes (CWE-120) when parsing CIP (Common Industrial Protocol) messages. An attacker who can reach the RSLinx Classic service over a network can send a single crafted CIP packet containing an oversized embedded message request, which crashes the service. The impact is availability-only: the RSLinx Classic service stops and must be manually restarted to recover, with no evidence of code execution or data compromise (CVSS 4.0 scores availability impact High and all other impacts None). Any organization running RSLinx Classic on workstations or servers that connect operations or maintenance software to Allen-Bradley/Rockwell controllers is potentially affected, particularly where the service is reachable from enterprise or internet-facing networks. As of this writing there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.
Remote Denial-of-Service in Rockwell Automation RSLinx Classic via Crafted CIP Packet
CVE-2026-9624 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software: the service fails to properly validate the data length field of incoming CIP packets (CWE-191), so a single crafted packet can crash it. An attacker with network access to the RSLinx service can trigger the crash remotely, with no privileges or user interaction required. The impact is availability-only — the RSLinx service stops and must be manually restarted, interrupting PC-to-controller communications, data collection, or monitoring that depends on it; confidentiality and integrity are unaffected. Any installation running RSLinx Classic where the service is reachable over the network (e.g., engineering workstations or servers in OT/manufacturing environments) is potentially affected. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept exists, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
Out-of-bounds write in Rockwell FactoryTalk Historian Machine Edition allows RCE
Rockwell Automation's FactoryTalk Historian Machine Edition contains an out-of-bounds write (CWE-787) that can be triggered by an attacker who holds low-level (low-privileged) authentication and can reach the historian over an adjacent network, as reflected in the CVSS 4.0 vector (AV:A/PR:L). By sending crafted input to the vulnerable service, the attacker corrupts memory beyond the intended buffer and achieves remote code execution on the host running the historian. Successful exploitation yields high impact to confidentiality, integrity, and availability on the affected system, effectively full compromise of that machine, with no modeled impact spreading to the wider network. Affected users are industrial operators, OEMs/machine builders, and plant sites running FactoryTalk Historian Machine Edition; the affected version ranges are specified in Rockwell Automation's security advisory and are not stated in the source data. Exploitation has not been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.
· Rockwell Automation FactoryTalk Historian Machine Editionlarge
Local privilege escalation to SYSTEM in Rockwell Automation FactoryTalk Activation Manager
CVE-2026-16675 is a local privilege escalation flaw in Rockwell Automation FactoryTalk Activation Manager caused by custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker holding ordinary Windows credentials on the host can hijack one of these console windows to obtain a SYSTEM-level command prompt, gaining full access to all files, processes, and system resources. Exposure is limited to Windows machines where the Activation Manager installer is run or repaired while an untrusted credentialed user is logged on locally. There is no evidence of exploitation so far: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.1% probability of exploitation in the next 30 days (1st percentile). The issue was assigned by Rockwell Automation's PSIRT and carries a CVSS 4.0 score of 8.5 (High) with local attack vector and low privileges required.
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case.
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
DLL Hijacking LPE in Rockwell Automation Redundancy Module Configuration Tool
Rockwell Automation's Redundancy Module Configuration Tool (RM3ConfigTool.exe) is vulnerable to a DLL search-order hijacking issue caused by incorrect default directory permissions (CWE-276). The binary searches directories listed in the system PATH for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users; a local attacker can plant a malicious DLL there, and when an administrator subsequently launches the tool, the malicious DLL is loaded and executes with Administrator or SYSTEM privileges. Exploitation requires low local privileges plus user interaction (an administrator running the tool), and yields full privilege escalation on the affected workstation. Any installation of the Redundancy Module Configuration Tool on Windows where writable PATH directories exist is affected; the available data does not specify affected version ranges. There is no known public proof-of-concept, no entry in the CISA KEV catalog, and EPSS estimates only about a 0.1% probability of exploitation within 30 days.
Authenticated DoS via Buffer Overflow in Rockwell FactoryTalk Historian ME
Rockwell Automation's FactoryTalk Historian Machine Edition contains a buffer overflow flaw (CWE-121) in its web interface. An attacker who is already on an adjacent network and holds valid, high-privileged credentials can send specially crafted requests to the web interface to trigger the overflow. Successful exploitation does not grant code execution or data theft; the impact is denial of service, causing the device to crash and become unresponsive until it is recovered. Only deployments running the affected FactoryTalk Historian Machine Edition web interface and reachable from an adjacent network segment are at risk. There is currently no known exploitation: the flaw is not in CISA's KEV, has a low EPSS score of 0.1%, and no public proof-of-concept is known.
· Rockwell Automation FactoryTalk Historian Machine Editionmoderate
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.