ZeroHour
Product

CompactLogix 5380

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Rockwell Automation security advisory (AV26-869)

Canada's Cyber Centre flags vulnerabilities across multiple Rockwell Automation ICS products including ControlLogix 5580 and RSLinx Classic.

Canadian Centre for Cyber Security advisory AV26-869, dated September 1, 2026, lists vulnerabilities in Rockwell Automation products: 1756-ENBT Module (all versions), ArmorStart LT (v2.001 and earlier), CompactLogix 5380 / ControlLogix 5580 (V33 and earlier plus several V34-V36 releases), and RSLinx Classic (V4.50 and earlier). It references Rockwell advisories SD1792, SD1794, SD1797, and SD1798 and urges users to apply updates as available.

Canadian Centre for Cyber Security · 14d agoAdvisory

Rockwell Automation Logix Platform

CISA warns Rockwell Automation Logix controllers (ControlLogix, CompactLogix, GuardLogix) up to V36.012 are affected by CVE-2026-9637 (CVSS 7.5).

CISA published ICS advisory ICSA-26-244-03 covering the Rockwell Automation Logix Platform. Affected products include ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 running firmware through V33 and selected V34-V36 releases. The underlying vulnerability is tracked as CVE-2026-9637 with a vendor CVSS v3 score of 7.5. The advisory provides guidance for industrial operators to update affected controllers.

CISA Advisories · 14d agoAdvisoryCVE-2026-9637

Related CVEs

  • Unauthenticated DoS in Rockwell Automation Logix controllers via CIP length flaw
    CVE-2026-9637 is a high-severity denial-of-service vulnerability in Rockwell Automation's Logix controller platform, caused by improper validation of input length during CIP (Common Industrial Protocol) message processing. An attacker who can send crafted CIP messages to an affected controller over the network can trigger the flaw without needing credentials or user interaction. Successful exploitation produces a major nonrecoverable fault (MNRF) that halts the controller and requires a physical power cycle to restore operation, making this an availability-only issue per the CVSS vector. Any site running an affected Logix controller is exposed, with the greatest risk to controllers reachable from untrusted networks such as IT/OT boundary links, VPNs, or internet-exposed EtherNet/IP interfaces. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
    · Rockwell Automation Logix platform controllers (the advisory references a table of affected platforms; individual models are not enumerated Affected model/firmware ranges per the Rockwell Automation security advisory; no specific version numbers provided in the source datamass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.