← All Advisories

CVE-2026-9653

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-9653

Key Details

CVECVE-2026-9653
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-07-14
Affected productsRockwell Automation 1756-EN2, 1756-EN3 and Rockwell Automation 1756-ENBT
Classified asCWE-354 (Improper Validation of Integrity Check Value)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Rockwell Automation1756-EN2, 1756-EN3
Rockwell Automation1756-ENBT
SubsystemsGeneral OT
SectorsMultiple

What to Know

A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after. (NVD)

What to Do

Monitor Rockwell Automation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9653
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9653