Denial-of-Service Vulnerability in Rockwell Automation Products
CVE-2026-84235

8.7HIGH

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84235?

A denial-of-service vulnerability has been identified in Rockwell Automation's Allen-Bradley ControlLogix and other related products. This vulnerability arises when a specially crafted CIP packet is transmitted to the affected module, causing it to crash. Recovery from this issue requires a manual restart of the device, posing significant operational risks for users dependent on reliable performance. It is vital for users to remain vigilant and consider mitigation strategies as outlined in the official security advisory.

Affected Version(s)

1756-ENBT Module All versions

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.