← All Advisories

CVE-2026-12659

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-12659

Key Details

CVECVE-2026-12659
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-07-14
Affected productsRockwell Automation The FLEX 5000® EtherNet/IP Adapter
Classified asCWE-415 (Double Free)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Rockwell AutomationThe FLEX 5000® EtherNet/IP Adapter
SubsystemsGeneral OT
SectorsMultiple

What to Know

A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O. (NVD)

What to Do

Monitor Rockwell Automation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-12659
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-12659