Rockwell Automation Logix Platform
CISA warns Rockwell Automation Logix controllers (ControlLogix, CompactLogix, GuardLogix) up to V36.012 are affected by CVE-2026-9637 (CVSS 7.5).
CISA published ICS advisory ICSA-26-244-03 covering the Rockwell Automation Logix Platform. Affected products include ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 running firmware through V33 and selected V34-V36 releases. The underlying vulnerability is tracked as CVE-2026-9637 with a vendor CVSS v3 score of 7.5. The advisory provides guidance for industrial operators to update affected controllers.
- Affects multiple Logix controller families through firmware V36.012
- CVE-2026-9637 carries a CVSS v3 base score of 7.5
- No active exploitation is reported in the advisory
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-9637 | Unauthenticated DoS in Rockwell Automation Logix controllers via CIP length flaw CVE-2026-9637 is a high-severity denial-of-service vulnerability in Rockwell Automation's Logix controller platform, caused by improper validation of input length during CIP (Common Industrial Protocol) message processing. An attacker who can send crafted CIP messages to an affected controller over the network can trigger the flaw without needing credentials or user interaction. Successful exploitation produces a major nonrecoverable fault (MNRF) that halts the controller and requires a physical power cycle to restore operation, making this an availability-only issue per the CVSS vector. Any site running an affected Logix controller is exposed, with the greatest risk to controllers reachable from untrusted networks such as IT/OT boundary links, VPNs, or internet-exposed EtherNet/IP interfaces. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days. Do: Review Rockwell Automation's security advisory for CVE-2026-9637 to determine whether your controller models and firmware are affected, and upgrade to the fixed firmware versions it specifies. Until patching, restrict network access to affected controllers by firewalling EtherNet/IP traffic (TCP/UDP 44818 and UDP 2222) to trusted hosts and removing any direct internet exposure. Because recovery requires a physical power cycle, plan maintenance windows and ensure controller logic backups are current before remediating. | 8.7 | <1% |
| mass≈1M+ installed Logix controllers across affected platforms, with on the order of tens of thousands reachable from untrusted networks |
View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) Compact GuardLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell…
This source does not provide full text. Read it at cisa.gov.