Status: UPDATED
| Advisory ID: CVE-2026-9653
Key Details
| CVE | CVE-2026-9653 |
| CVSS Score / Version | 8.7 (High) / CVSS v4.0 |
| Updated | 2026-07-14 |
| Affected products | Rockwell Automation 1756-EN2, 1756-EN3 and Rockwell Automation 1756-ENBT |
| Classified as | CWE-354 (Improper Validation of Integrity Check Value) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after. (NVD)
What to Do
Monitor Rockwell Automation's web page for any future patch releases.
References