Rockwell Automation security advisory (AV26-869)
Canada's Cyber Centre flags vulnerabilities across multiple Rockwell Automation ICS products including ControlLogix 5580 and RSLinx Classic.
Canadian Centre for Cyber Security advisory AV26-869, dated September 1, 2026, lists vulnerabilities in Rockwell Automation products: 1756-ENBT Module (all versions), ArmorStart LT (v2.001 and earlier), CompactLogix 5380 / ControlLogix 5580 (V33 and earlier plus several V34-V36 releases), and RSLinx Classic (V4.50 and earlier). It references Rockwell advisories SD1792, SD1794, SD1797, and SD1798 and urges users to apply updates as available.
- Affects ControlLogix 5580, CompactLogix 5380, 1756-ENBT, ArmorStart LT, and RSLinx Classic
- References Rockwell security advisories SD1792, SD1794, SD1797, and SD1798
- No CVE IDs or exploitation details included; patching urged for OT environments
Full article120 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-869
Date: September 1, 2026
As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products:
1756-ENBT Module
All versions
ArmorStart LT
Prior to or equal to v2.001
CompactLogix 5380 / ControlLogix 5580
Prior to or equal to V33
V34.011 to V34.014
V35.011 to V35.013
V36.011 to V36.012
RSLinx Classic
Prior to or equal to V4.50
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
SD1797 | Security Advisory | Rockwell Automation | US
SD1798 | Security Advisory | Rockwell Automation | US
SD1794 | Security Advisory | Rockwell Automation | US
SD1792 | Security Advisory | Rockwell Automation | US
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/rockwell-automation-security-advisory-av26-869