← All Advisories

CVE-2026-0646

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-0646

Key Details

CVECVE-2026-0646
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-06-17
Affected productsRockwell Automation FLEX I/O EtherNet/IP Adapters
Classified asCWE-401 (Missing Release of Memory after Effective Lifetime)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Rockwell AutomationFLEX I/O EtherNet/IP Adapters
SubsystemsGeneral OT
SectorsMultiple

What to Know

A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing connection to its associated I/O modules, requiring a manual reset to recover. (NVD)

What to Do

Monitor Rockwell Automation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0646
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0646