Rockwell Automation's Logix controllers, the programmable logic controllers that run production lines in factories worldwide, can be pushed into a fault state by a single malformed network message from somebody who has not logged in to anything.
CISA published six advisories covering Rockwell products on September 1, spanning eleven CVEs across controllers, communications software, a historian appliance and two Windows tools. CISA says no public exploitation of any of them has been reported to it.
One packet, one power cycle
The controller flaw is CVE-2026-9637, rated 7.5 under CVSS 3.1 and 8.7 under CVSS 4.0. The Logix platform does not properly validate input length while processing CIP messages, the protocol Rockwell equipment uses to talk to engineering software and other devices, and a crafted message triggers what Rockwell calls a major nonrecoverable fault. The controller stops and has to be power cycled. ControlLogix 5580, CompactLogix 5380, GuardLogix 5580 and Compact GuardLogix 5380 are affected through firmware V36.012, with fixes in 34.015, 35.014, 36.013 and 37.011. The detail is in CISA's advisory.
A second advisory covers the same controller families plus the CompactLogix 5480, and carries a CVE identifier from 2021: CVE-2021-42260, also rated 7.5. Corrupt crafted data drives an infinite loop and produces the same fault, but recovery costs more. A safety controller needs a full program download to come back, and a non-safety controller needs a stage 2 reset. The same four firmware versions fix it.
The highest scores in the set belong to RSLinx Classic, the communications software that sits between Rockwell hardware and the tools on an engineer's workstation. Four unauthenticated remote denial-of-service issues in version 4.50 and earlier each crash the service until it is restarted. CVE-2026-9621 and CVE-2026-9622 are rated 8.6 under CVSS 3.1 and 9.2, critical, under CVSS 4.0. CVE-2026-9624 and CVE-2026-9625 are rated 7.5 and 8.7. Version 4.60 fixes all four.
The advisory with no version to install
The one to read closely is the Historian ME advisory, because it lists no fixed version at all. CVE-2025-12768, rated 8.0, is an out-of-bounds write that CISA says an attacker with low-level authentication on an adjacent network could use to run code on the device. CVE-2026-12661, rated 4.5, is a stack buffer overflow reachable through the web interface that crashes the appliance. Series B 5.202 and Series C 7.101 are affected, and the remediation section offers only Rockwell's security best practices and a PSIRT contact address. CISA tags it for chemical, critical manufacturing, food and agriculture, healthcare, and water and wastewater systems, the widest sector footprint in the batch.
Two quiet routes to SYSTEM on a workstation
The remaining pair need a local foothold first. In FactoryTalk Activation Manager V5.02 and below, CVE-2026-16675, rated 7.8, comes from installer actions that spawn visible console windows running with SYSTEM privileges during an install or repair, and somebody who already holds Windows credentials can hijack one to get a SYSTEM command prompt. V5.03 fixes it; an anonymous researcher reported it through Rockwell. The Redundancy Module Configuration Tool advisory covers CVE-2026-9633 and CVE-2026-9634, both rated 7.3: both tools search the system path for a DLL, and some of those directories are writable by ordinary users by default, so a planted DLL runs elevated when an administrator opens the tool. Version 10.01.00 fixes both, and neither is remotely exploitable.
Patch the network-reachable ones first
The order to work in is not the CVSS order. The RSLinx bugs and the two controller faults need no credentials and no user interaction, and the controller faults stop a machine rather than a service. Rockwell has fixes for all of it except Historian ME, where the only answer today is CISA's standing control-systems advice: keep these devices off the internet and behind firewalls, away from the business network. Rockwell's security advisories page carries the vendor versions.
Six advisories against one vendor in a day is a batch, not an emergency. The shape is what stands out. July's Rockwell and ABB batch and the Siemens and Rockwell login bypass were largely about getting in. Most of this set is about stopping equipment, which on a production line is its own kind of loss.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.