Junglewise Threat Intelligence

CVE-2026-9637: Rockwell Automation Logix Platform denial-of-service in CIP message processing

CVE-2026-9637 · Severity: info · CVSS 8.7 · Published 2026-09-01

Technologies: Rockwell Automation ControlLogix 5580, Rockwell Automation GuardLogix 5580, Rockwell Automation CompactLogix 5380. Vendors: Rockwell Automation.

Executive brief

Rockwell Automation's Logix control systems—used in industrial automation for manufacturing and process control—contain a denial-of-service vulnerability in their CIP (Common Industrial Protocol) message handling. An attacker can exploit this by sending a specially crafted message, causing the controller to crash and enter an irrecoverable fault state that requires manual power cycling to restore, disrupting production operations.

Technical details

The vulnerability is a buffer overflow (CWE-119) in CIP message processing on Logix platforms. The root cause is improper validation of input length during message parsing, allowing an attacker to trigger a major nonrecoverable fault (MNRF) that crashes the controller. The attack is network-accessible and requires no authentication or user interaction. An attacker can repeatedly send malformed CIP messages to cause denial of service; remediation requires upgrading to corrected firmware versions (V37.011, V36.013, V35.014, or V34.015) for each affected product line.

Affected products

  • Rockwell Automation ControlLogix 5580 V33 and prior, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
  • Rockwell Automation CompactLogix 5380 V33 and prior, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
  • Rockwell Automation GuardLogix 5580 V33 and prior, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
  • Rockwell Automation CompactGuardLogix 5380 V33 and prior, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012

Timeline

  • 2026-09-01: disclosed: Security advisory SD1792 published by Rockwell Automation
  • 2026-09-01: patched: Corrected firmware versions available: V37.011, V36.013, V35.014, V34.015
  • 2026-09-01: kev added: Listed as Known Exploited Vulnerability (KEV)

References

Related threats