← All Advisories

CVE-2026-9637

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-9637

Key Details

CVECVE-2026-9637
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-09-01
Affected productsRockwell Automation CompactLogix® 5380 / ControlLogix® 5580
Classified asCWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Rockwell AutomationCompactLogix® 5380 / ControlLogix® 5580
SubsystemsGeneral OT
SectorsMultiple

What to Know

A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover (NVD)

What to Do

Monitor Rockwell Automation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9637
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9637