Denial-of-Service Vulnerability in RSLinx Classic by Rockwell Automation
CVE-2026-9621
9.2CRITICAL
Key Information:
- Vendor
Rockwell Automation
- Status
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-9621?
A denial-of-service security issue exists in RSLinx® Classic due to improper handling of specially crafted CIP packets. An attacker can exploit this vulnerability by sending a malformed packet to the service, causing it to crash. This requires a manual restart of the RSLinx® Classic service to restore functionality. Organizations using this service must implement mitigations and monitor their systems to avoid disruptions caused by this security concern.
Affected Version(s)
RSLinx Classic® V4.50 and prior