The Cybersecurity and Infrastructure Security Agency published six Rockwell Automation advisories on September 1, 2026, covering 11 vulnerabilities across industrial controllers, communications software, engineering utilities, activation management and an embedded historian. The affected products include RSLinx Classic, ControlLogix and CompactLogix platforms, FactoryTalk Activation Manager, the Redundancy Module Configuration Tool and FactoryTalk Historian Machine Edition.
For maintenance and reliability leaders, the most important point is not the vulnerability count. It is the range of operational roles represented by the affected products. Some issues can make software or controllers unavailable; others can elevate privileges on engineering workstations or permit code execution on a historian module. This means remediation ownership may be divided among controls, IT, cybersecurity, maintenance and operations even though the production consequence belongs to the plant as a whole.
The response should therefore be coordinated as reliability work: identify exact versions, evaluate the physical consequence of loss of function, test corrections, preserve a recovery path and verify equipment behavior after the change.
Key Takeaways
- CISA’s six September 1 advisories cover 11 vulnerabilities across several layers of a Rockwell Automation environment.
- The most direct plant consequence is loss of availability, including controller faults that may require a power cycle to recover.
- Not every issue is remotely exploitable. Some require authenticated or local access, and the affected versions differ substantially.
- CISA says no known public exploitation of the new Logix denial-of-service vulnerability has been reported; the available evidence does not support describing it as actively exploited.
- Plants should prioritize by cyber exposure, process criticality, recovery difficulty and safety consequence – not by CVSS score alone.
- Updates to OT systems should be tested and performed under formal change control, with backups, rollback plans and post-change operational verification.
QUICK TAKE
The new Rockwell Automation advisories are an uptime issue as much as a cybersecurity issue. A controller denial of service, compromised engineering utility or unavailable historian can interrupt production even when no motor, coupling or gearbox is mechanically damaged. Plants need a joint controls-maintenance-cybersecurity response that reduces exposure without turning an urgent patch into an avoidable outage.
What CISA Disclosed
CISA released the following six advisories on September 1. Together, they cover four broad risk types: denial of service, local privilege escalation, authenticated remote code execution and loss of historian availability.
| Advisory | Affected product or platform | Confirmed issue | Plant-level concern |
|---|---|---|---|
| ICSA-26-244-01 | RSLinx Classic 4.50 and earlier | Four malformed-packet denial-of-service vulnerabilities | Loss of communications or an unresponsive application can disrupt engineering access, data exchange or troubleshooting workflows. Rockwell lists version 4.60 as the corrected release. |
| ICSA-26-244-02 | Redundancy Module Configuration Tool | Two local privilege-escalation issues involving unsafe DLL loading conditions | A user with local access may be able to execute code with elevated privileges when the utility is run. Rockwell lists version 10.01 as the corrected release. |
| ICSA-26-244-03 | ControlLogix 5580, CompactLogix 5380, GuardLogix 5580 and Compact GuardLogix 5380 firmware | Improper input-length validation during Common Industrial Protocol message processing | A crafted message can produce a major nonrecoverable fault requiring a power cycle. Corrected firmware varies by release branch. |
| ICSA-26-244-04 | FactoryTalk Activation Manager 5.02 and earlier | Local privilege escalation during installation or repair operations | An authenticated Windows user could obtain SYSTEM-level access. Rockwell lists version 5.03 as the corrected release. |
| ICSA-26-244-05 | Multiple ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix and Compact GuardLogix versions | Crafted-data denial of service associated with an affected software component | Controller availability can be affected; corrected firmware thresholds differ by controller family and major version. |
| ICSA-26-244-06 | FactoryTalk Historian ME Series B 5.202 and Series C 7.101 | Authenticated remote code execution and denial of service | An attacker with the required access could execute code or make the module unresponsive. Rockwell lists Series B 5.203 and Series C 7.102 as corrected firmware. |
The table is a triage summary, not a substitute for the advisories. Plants should verify the catalog number, major and minor firmware revision, installed software version, architecture and vendor compatibility requirements before scheduling a change.
By the Numbers
- 6: New CISA Rockwell Automation advisories released September 1, 2026
- 11: CVEs covered across those advisories
- 4: RSLinx Classic denial-of-service vulnerabilities
- 2: Redundancy Module Configuration Tool privilege-escalation vulnerabilities
- 2: Historian ME vulnerabilities
- 1 each: Logix platform denial of service, FactoryTalk Activation Manager privilege escalation and broader controller-family denial of service
Why This Is a Reliability Story
The advisories affect different points in the control-system chain. A controller firmware flaw can directly remove a control function from service. A communications application failure can obstruct visibility or engineering access. A compromised configuration utility can undermine the workstation used to maintain redundant control assets. A historian problem can remove data that operators and reliability teams depend on for troubleshooting and performance review.
That does not mean the disclosed vulnerabilities have caused gearbox damage, motor failure or unsafe process behavior. The advisories do not establish those outcomes. The immediate confirmed risk is digital availability or privilege compromise. Physical consequences depend on the process design, protective functions, controller role, fail-safe behavior and operating state when a disruption occurs.
The distinction matters. A plant should neither dismiss the issue as an IT-only problem nor claim that every vulnerable controller threatens mechanical damage. The defensible approach is to map each affected digital asset to the process and equipment that depend on it.
RELIABILITY IMPACT
Vulnerability severity describes properties of the cyber flaw. It does not fully describe production consequence. A moderate issue on a workstation with limited process access may present less operational risk than an availability flaw on a controller whose recovery requires a physical power cycle during continuous production.
The Logix Denial-of-Service Issue Deserves Particular Attention
CISA’s Logix platform advisory describes improper validation of input length during Common Industrial Protocol message processing. Successful exploitation can cause a major nonrecoverable fault, requiring a power cycle to restore the affected controller.
That recovery requirement changes the maintenance calculation. A software fault that can be cleared remotely is operationally different from one that may require authorized personnel to reach a cabinet, follow site procedures, cycle equipment and recommission the affected part of the process. Remote or difficult-to-access installations, redundant architectures and safety-related applications require especially careful planning.
CISA reports that no known public exploitation specifically targeting this vulnerability had been reported at publication. It is also not listed in CISA’s Known Exploited Vulnerabilities Catalog as of September 2. That should prevent alarmist claims, but it should not stop plants from assessing exposure. Absence of reported exploitation is not proof that a vulnerable installation is acceptably protected.
The new disclosure also differs from the recently reported Siemens S7 targeting activity. That story involved reported hostile activity against exposed PLC environments. The Rockwell advisories primarily create an asset-identification and remediation problem. Plants should not merge the two situations into a single claim of active exploitation.
Why OT Patching Cannot Be Managed Like Office Software
NIST’s Guide to Operational Technology Security emphasizes that OT cybersecurity must account for performance, reliability and safety requirements. In practice, an industrial update may affect communications, redundancy, safety signatures, I/O behavior, HMI integration, licensing, historian continuity or the ability to restore a known-good project.
For this reason, “patch immediately” is incomplete operational guidance. Plants should move promptly, but through a controlled process that answers four questions:
- What exactly is affected? Identify software versions, controller catalog numbers, firmware branches, historian series and the engineering stations on which tools are installed.
- What is the exposure? Determine network reachability, required authentication, local-user access, remote-access paths and whether the asset is reachable from less trusted networks.
- What could remediation disrupt? Check compatibility with controllers, communication modules, HMIs, drives, safety systems, redundancy configurations and vendor-supported combinations.
- How will the plant recover? Preserve verified backups, controller projects, configurations, activation information and a tested rollback or replacement path.
NIST’s OT asset-management practice guide reinforces the first step: a useful inventory records enough attributes to distinguish the asset and its state, rather than merely noting that a plant uses “Rockwell PLCs.” These advisories demonstrate why product family alone is insufficient. Risk depends on exact versions and deployment context.
COMMON MISTAKE
Searching only for controller model names. Several of the September 1 advisories affect software on engineering workstations or an embedded historian module, not just PLC firmware. A controller-only inventory can therefore miss systems that influence configuration, communications, licensing and recovery.
Plant Response Checklist
Use the following as a planning aid alongside the Rockwell advisories, OEM instructions and site-specific change-control and safety procedures:
- Assign an owner to review all six CISA advisories, not only the controller bulletin.
- Inventory exact catalog numbers, hardware series, firmware revisions and installed software versions.
- Identify which affected assets support critical, continuous, safety-related or difficult-to-recover processes.
- Document network paths, remote access and local-user access to affected controllers and engineering stations.
- Confirm the applicable corrected release or mitigation directly with Rockwell Automation.
- Review firmware and software compatibility across controllers, modules, HMIs, drives, historians and redundant systems.
- Back up projects, configurations, license information and known-good files; verify that the recovery method is usable.
- Test updates in a representative environment whenever feasible.
- Schedule production changes through the plant’s management-of-change process and follow applicable hazardous-energy-control procedures.
- Define pre-change and post-change acceptance criteria, including controller faults, I/O health, communications, redundancy state, alarms and historian data flow.
- After restart, verify the controlled process and connected equipment under stable operating conditions.
- Record the final version, change date, approver, test result and any deferred remediation.
What Maintenance Teams Should Watch After the Change
Post-update verification should extend beyond a successful software installation. Controls and operations personnel should confirm that programs, communications, I/O, safety functions, redundancy and data collection are operating as intended. Maintenance and reliability teams should compare the machine’s behavior with credible pre-change baselines.
For motor-driven equipment, useful checks may include speed, load, motor current, vibration, temperature, process output and alarm behavior. The objective is not to imply that a cyber update should change gearbox condition. It is to establish that the complete system returned to its expected state and to detect a configuration or restart problem before it is misdiagnosed as mechanical failure.
Plants can use the same system-level commissioning discipline described in Seven Restart Checks That Protect Industrial Equipment. Where a machine’s behavior is abnormal, Gearbox Vibration Analysis and the Gearbox Bearing Failure Troubleshooting Guide can help distinguish a mechanical condition from a control-layer or process change.
PULL QUOTE
“The safest remediation plan treats the controller, engineering workstation and connected machine as one operational system.”
Risks, Limitations and Unanswered Questions
The advisories establish affected products, vulnerability mechanisms and vendor-recommended corrections. They do not reveal how many plants run the affected versions, how exposed those installations are or whether each facility can install a corrected release without compatibility work.
There is also an important exploitation-status limitation. CISA’s advisory does not report known public exploitation of CVE-2026-9637, despite a conflicting exploited indicator reported in one location within Rockwell material. Until the vendor or CISA clarifies that discrepancy, the responsible wording is that exploitation is not confirmed by the current authoritative public evidence.
Finally, remediation priority cannot be determined from CVSS scores alone. A locally exploitable workstation issue may become important where shared engineering stations, weak account controls or routine administrator use create the required conditions. Conversely, a remotely reachable controller flaw may be materially reduced by well-designed segmentation and access controls, though those controls do not replace the vendor correction.
Questions to Ask Your Plant
- Do we know every location where RSLinx Classic, FactoryTalk Activation Manager and the redundancy configuration tool are installed?
- Which affected controllers would require a production shutdown or physical visit to recover from a major nonrecoverable fault?
- Can our inventory distinguish controller family, catalog number, hardware series and exact firmware revision?
- Have we verified that corrected firmware is compatible with our I/O, communication modules, safety configuration, HMIs, drives and redundancy design?
- Can we restore a known-good controller project and configuration if an update fails?
- What operating evidence will prove that the process and connected equipment returned to normal after remediation?
- Who has final authority to accept the cyber risk, approve the production change and stop the restart if acceptance criteria are not met?
What Plants Should Do This Week
- Review the six September 1 CISA advisories as one coordinated work package.
- Run version-specific inventory queries across controllers, historian modules and engineering workstations.
- Escalate exposed, critical or difficult-to-recover assets for controls-engineering review.
- Obtain the applicable correction and compatibility information from Rockwell Automation.
- Build tested remediation and recovery plans before the next available maintenance window.
- Apply compensating controls where an update must be deferred, then document the residual risk and target date.
Industrial Gearbox Solutions Editorial Perspective
The September 1 Rockwell disclosures show why industrial cybersecurity increasingly belongs inside reliability planning. The affected products do not sit in one neat technical category: they support control, communications, configuration, licensing and historical data. Their failures can therefore cross traditional departmental boundaries before the plant understands the operational consequence.
The correct response is neither panic nor passive deferral. It is disciplined asset identification, consequence-based prioritization, tested change control and system-level verification. A vulnerability bulletin may begin with a CVE, but the plant decision ends with a practical question: can the organization reduce the exposure while preserving safe, predictable operation and a credible recovery path?
Frequently Asked Questions
Are the newly disclosed Rockwell Automation vulnerabilities being actively exploited?
CISA reported no known public exploitation of the new Logix denial-of-service vulnerability at publication, and it was not in CISA’s Known Exploited Vulnerabilities Catalog on September 2, 2026. Plants should monitor CISA and Rockwell for updates rather than describe exploitation as confirmed.
Which Rockwell products are affected?
The six CISA advisories cover RSLinx Classic, the Redundancy Module Configuration Tool, several ControlLogix and CompactLogix platforms, FactoryTalk Activation Manager and FactoryTalk Historian Machine Edition. Exact affected versions vary, so product names alone are not sufficient for inventory.
Should plants install every update immediately?
Plants should assess and remediate promptly, but OT updates should follow tested change control. Verify the exact affected version, operational criticality, compatibility, backup and rollback path before changing production systems. Where remediation must be deferred, apply vendor-recommended mitigations and document the residual risk.
Can these vulnerabilities damage a gearbox or motor?
The advisories primarily establish cyber consequences such as denial of service, privilege escalation and code execution. They do not document gearbox or motor damage. Physical consequences would depend on the affected controller’s role, process design, safeguards, operating state and recovery behavior.
Why should maintenance be involved in a cybersecurity advisory?
Maintenance understands asset criticality, access constraints, outage windows, restart requirements and machine-condition baselines. Cybersecurity and controls personnel understand exposure and technical remediation. Both perspectives are needed to reduce cyber risk without creating unnecessary production or recovery risk.
Recommended Reading
- What the Siemens S7 Threat Means for Plant Reliability – compare confirmed targeting activity with the remediation-centered Rockwell disclosures.
- Seven Restart Checks That Protect Industrial Equipment – use system-level commissioning discipline after controller or workstation changes.
- Gearbox Vibration Analysis: What the Data Really Means – establish and interpret mechanical baselines after a control-system change.
- Gearbox Predictive Maintenance Guide – connect data availability and monitoring continuity to reliability decisions.
- Gearbox Bearing Failure Troubleshooting Guide – separate mechanical evidence from possible control or process causes.
- ABB Variable Frequency Drive Guide – supporting context on the drive layer between PLC commands and motor-driven equipment.
Source and Evidence Summary
Primary and Authoritative Sources
- CISA ICSA-26-244-01: Rockwell Automation RSLinx Classic – September 1, 2026. Confirms affected RSLinx versions, four CVEs, denial-of-service effects and mitigations.
- CISA ICSA-26-244-02: Redundancy Module Configuration Tool – September 1, 2026. Confirms two local privilege-escalation issues and affected utility versions.
- CISA ICSA-26-244-03: Rockwell Automation Logix Platform – September 1, 2026. Confirms the CIP input-validation flaw, affected firmware branches and major nonrecoverable fault consequence.
- CISA ICSA-26-244-04: FactoryTalk Activation Manager – September 1, 2026. Confirms the local privilege-escalation mechanism and affected versions.
- CISA ICSA-26-244-05: ControlLogix and CompactLogix Families – September 1, 2026. Confirms crafted-data denial-of-service risk and version-specific corrected firmware thresholds.
- CISA ICSA-26-244-06: Rockwell Automation Historian ME – September 1, 2026. Confirms affected Historian ME firmware and the code-execution and denial-of-service issues.
- Rockwell Automation Security Advisories – vendor portal. Primary vendor source for corrections, product-specific advisories and future revisions.
- Rockwell Automation Product Compatibility and Download Center – vendor source for current downloads and compatibility validation.
- NIST SP 800-82 Rev. 3: Guide to Operational Technology Security – September 2023. Authoritative context for balancing OT security with reliability, performance and safety.
- NIST NCCoE SP 1800-23: Energy Sector Asset Management – authoritative practice guide supporting detailed OT asset inventory and baselining.
- CISA Known Exploited Vulnerabilities Catalog – checked September 2, 2026, for exploitation status.
