Denial-of-Service Vulnerability in Logix Platforms by Rockwell Automation
CVE-2026-9637
8.7HIGH
Key Information:
- Vendor
Rockwell Automation
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-9637?
A significant vulnerability has been identified in Rockwell Automation's Logix platforms which arises from insufficient validation of input lengths during the processing of CIP messages. Exploitation of this weakness may lead to a nonrecoverable fault, necessitating a complete power cycle to restore normal operations. This could have serious implications for operational continuity and system stability, making it crucial for users to understand the potential risks and take appropriate action.
Affected Version(s)
CompactLogix® 5380 / ControlLogix® 5580 V33 and prior, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012