Junglewise Threat Intelligence

CVE-2026-9653: Rockwell Automation 1756-EN series denial of service in CIP packets

CVE-2026-9653 · Severity: info · CVSS 8.7 · Published 2026-07-14

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation ControlLogix communication modules are vulnerable to a flaw that allows a remote attacker to disrupt industrial network connections. By sending specially crafted data packets, an attacker can cause a denial-of-service condition, temporarily disconnecting the module from the industrial network. While the device is designed to recover immediately, repeated attacks could lead to sustained operational downtime and loss of visibility into industrial processes.

Technical details

A denial-of-service vulnerability exists in the Rockwell Automation 1756-EN2, EN3, and ENBT communication modules due to improper validation of Common Industrial Protocol (CIP) Implicit Connection packets (CWE-354). A remote, unauthenticated attacker can exploit this by sending crafted packets over the network to the affected module. Successful exploitation results in the disruption of device connections, although the module is reported to recover immediately after the packet is processed. Firmware version V12.002 provides a fix for EN2 and EN3 modules; however, the ENBT module is discontinued and will not receive a patch.

Affected products

  • Rockwell Automation 1756-EN2 V12.001 and before
  • Rockwell Automation 1756-EN3 V12.001 and before
  • Rockwell Automation 1756-ENBT V6.006

Timeline

  • 2026-07-14: advisory: Initial release of Rockwell Automation advisory SD1780
  • 2026-07-14: disclosed

References

Related threats