← All Advisories

CVE-2026-11317

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-11317

Key Details

CVECVE-2026-11317
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-06-17
Affected productsRockwell Automation CompactLogix, ControlLogix
Classified asCWE-404 (Improper Resource Shutdown or Release)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Rockwell AutomationCompactLogix, ControlLogix
SubsystemsGeneral OT
SectorsMultiple

What to Know

A denial of service security issue exists in the

affected product. The security issue stems from a fault occurring when a

crafted CIP message is sent. Devices with less memory are more likely to be

affected. This can result in a major nonrecoverable fault (MNRF). A program

download is required to recover. (NVD)

What to Do

Monitor Rockwell Automation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-11317
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-11317