Status: UPDATED
| Advisory ID: CVE-2026-9637
Key Details
| CVE | CVE-2026-9637 |
| CVSS Score / Version | 8.7 (High) / CVSS v4.0 |
| Updated | 2026-09-01 |
| Affected products | Rockwell Automation CompactLogix® 5380 / ControlLogix® 5580 |
| Classified as | CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover (NVD)
What to Do
Monitor Rockwell Automation's web page for any future patch releases.
References