Denial-of-Service Vulnerability in Rockwell Automation Logix Controllers
Security Advisory Brief
The Cybersecurity and Infrastructure Security Agency (CISA) published industrial control system advisory ICSA-26-244-03 on September 1, 2026, disclosing a denial-of-service vulnerability affecting the Rockwell Automation Logix controller platform. The flaw, tracked as CVE-2026-9637, was self-reported to CISA by Rockwell Automation and carries a CVSS v3.1 base score of 7.5 and a CVSS v4.0 base score of 8.7. It affects four of the most widely deployed controller families in modern industrial environments: ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380. Because these controllers sit at the heart of process and machine control across power generation, water treatment, oil and gas, manufacturing, and transportation, the population of potentially affected devices is substantial.
The underlying defect is an improper restriction of operations within the bounds of a memory buffer, classified under CWE-119. The affected firmware does not correctly validate the length of input supplied during Common Industrial Protocol (CIP) message processing. An attacker who can deliver a specially crafted CIP message to the controller over the network can drive the device into a major nonrecoverable fault, commonly referred to as an MNRF. A controller in this state stops executing its control program and does not return to service on its own; recovery requires a physical power cycle of the affected unit. The CVSS vectors describe an attack that is executed across the network, requires low attack complexity, needs no privileges, and requires no user interaction, and the impact is confined entirely to availability with no loss of confidentiality or integrity.
The risk profile of this vulnerability is defined less by what an attacker gains than by what a plant loses. In an information technology context an availability-only flaw is often treated as a secondary concern, but in an operational technology context availability is the primary security objective, and an unplanned controller fault translates directly into stopped production, dropped process control, and in some configurations an unplanned safety trip. That concern is sharpened by the inclusion of the GuardLogix 5580 and Compact GuardLogix 5380 safety controllers in the affected set, where an induced fault carries safety-instrumented-system consequences rather than purely economic ones. Rockwell Automation has published corrected firmware for every affected version family, but no workaround has been identified for organizations that cannot upgrade immediately, which means firmware remediation and network exposure reduction are the only levers available. CISA reports no known public exploitation specifically targeting this vulnerability at this time.
Threats and Vulnerabilities
CVE-2026-9637, with a CVSS v3.1 score of 7.5 and a CVSS v4.0 score of 8.7, is a denial-of-service vulnerability in the Rockwell Automation Logix platform arising from improper validation of input length during CIP message processing. The affected versions are ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 at firmware V33 and earlier, V34.011 through V34.014, V35.011 through V35.013, and V36.011 through V36.012. Exploitation requires only network reachability to the controller's CIP service, which is exposed over EtherNet/IP on TCP and UDP port 44818 and, for implicit I/O messaging, UDP port 2222. Because CIP on these controllers accepts unauthenticated explicit messaging by default in most deployed configurations, an attacker positioned anywhere with routed or bridged access to the control network segment can attempt the attack without credentials, without a foothold on an engineering workstation, and without any interaction from an operator. A single malformed message is sufficient to place the controller into a major nonrecoverable fault, and repeating the message after each recovery would allow an attacker to keep the device out of service indefinitely. Rockwell Automation has corrected the defect in firmware V34.015, V35.014, V36.013, and V37.011, with the specific target release determined by the version family currently installed on the controller.
Client Impact
The operational consequence of successful exploitation is an abrupt and total loss of control for every process, machine, or safety function executing on the affected controller. A major nonrecoverable fault is not a transient condition that clears on retry; the controller halts, outputs go to their configured fault state, and the device remains offline until someone physically power cycles it. For organizations running distributed control architectures with dozens or hundreds of ControlLogix and CompactLogix chassis across a site, the recovery burden alone is significant, and for remote or unmanned assets such as pumping stations, substations, and pipeline facilities, a fault that requires an on-site power cycle can mean hours of lost production and an emergency truck roll. Where GuardLogix and Compact GuardLogix safety controllers are in scope, the induced fault will drive the safety instrumented function to its de-energized state, producing an unplanned shutdown that carries its own startup risk, equipment stress, and process disruption. Organizations should also anticipate that upgrading firmware on these platforms is not a routine software patch: it typically requires a controller mode change, a validated maintenance window, and in regulated environments a re-validation of the safety application, which means remediation timelines will be measured in maintenance cycles rather than days.
The compliance consequence follows directly from the operational one. Entities subject to NERC CIP must account for CVE-2026-9637 under CIP-007-6 R2, which requires evaluation of applicable security patches within 35 calendar days of release and either installation or a documented, dated mitigation plan; the absence of a vendor workaround makes that mitigation plan harder to substantiate on compensating controls alone and increases the weight placed on network segmentation evidence. Organizations aligning to IEC 62443-3-3 will find this vulnerability directly implicates system requirements SR 7.1 and SR 7.2, which address denial-of-service protection and resource management for control systems, and it reinforces the zone-and-conduit control expected under SR 5.1. Water and wastewater utilities, pipeline operators under TSA security directives, and manufacturers operating to NIST SP 800-82 guidance should treat the presence of unpatched affected controllers as a documented, time-bound risk acceptance rather than an open item, and should be prepared to demonstrate that CIP messaging to these controllers is constrained to an authorized engineering population.
Mitigations
1898 & Co. recommends the following actions to reduce exposure to CVE-2026-9637.
- Inventory every ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 controller in the environment and record the exact firmware revision on each, then classify each device as affected, not affected, or unknown. Controllers at V33 or earlier, V34.011 through V34.014, V35.011 through V35.013, or V36.011 through V36.012 are in scope, and any controller whose revision cannot be confirmed should be treated as affected until proven otherwise.
- Upgrade affected controllers to the corrected firmware on the vendor-defined upgrade path: V34.015 for controllers on V34.011 through V34.014, V35.014 for controllers on V35.011 through V35.013, V36.013 for controllers on V36.011 through V36.012, and V37.011 for controllers at V33 or earlier. Schedule the work through the normal change-management and maintenance-window process, and for safety controllers include the safety application re-validation required by the site's functional safety program.
- Confirm that no affected controller is reachable from the internet and that CIP and EtherNet/IP traffic on TCP and UDP port 44818 and UDP port 2222 is not permitted to traverse the boundary between the enterprise network and the control network. Where such traffic is required for legitimate engineering or historian access, constrain it to an explicitly enumerated set of source addresses through firewall policy or a unidirectional gateway, and verify the rule set by test rather than by review of the configuration alone.
- Deploy or tune network detection for anomalous CIP activity on the control network, including malformed or oversized CIP messages, CIP explicit messaging originating from hosts that are not part of the sanctioned engineering population, and any sudden change in controller operational mode or a transition to a faulted state. Correlate controller fault events with the network record so that an operational fault can be distinguished from an induced one within the same investigation.
- Establish and rehearse a recovery procedure for a controller in a major nonrecoverable fault state, covering who is authorized to power cycle the affected unit, how the control program and configuration are restored and verified, how a safety trip is cleared and the process restarted, and how the event is preserved as evidence. Confirm that current, tested controller program backups exist for every in-scope device before beginning any firmware upgrade campaign.
Applying these actions together reduces both the likelihood that a malformed CIP message reaches an affected controller and the operational cost if one does.
1898 & Co. Response
1898 & Co. has supported industrial and critical infrastructure organizations through vulnerability disclosures affecting the Rockwell Automation control platform for many years, and our operational technology security team works alongside plant engineering and reliability staff rather than around them. We help clients build and maintain an accurate controller inventory with firmware revision detail, translate a vendor advisory into a site-specific applicability determination, and sequence firmware remediation into maintenance windows in a way that respects production commitments and functional safety obligations.
Our managed threat detection and response service is built specifically for operational technology environments, with analysts who understand CIP, EtherNet/IP, and the behavior of Logix controllers under normal and abnormal conditions. That grounding matters for a vulnerability of this kind, because the difference between a controller fault caused by a failing power supply and one induced by a crafted message is visible only when process telemetry and network evidence are analyzed together. We provide threat hunt content, detection engineering, and incident response support scoped to the control network rather than adapted from information technology tooling.
For organizations working through NERC CIP, IEC 62443, TSA, or state regulatory obligations, 1898 & Co. provides assessment and advisory support that documents the applicability determination, the mitigation plan, and the segmentation evidence in the form auditors expect. We work alongside clients to close the gap between an advisory being published and a defensible position being recorded, and we remain available to support firmware upgrade planning, network architecture review, and post-incident analysis for the affected Logix platforms.
Sources
- CISA ICS Advisory ICSA-26-244-03 — Rockwell Automation Logix Platform
- NVD Entry — CVE-2026-9637
- MITRE CVE Record — CVE-2026-9637
- Rockwell Automation Security Advisories — Trust Center
- MITRE CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
- CISA — Industrial Control Systems Recommended Practices