Rockwell Automation recently announced the release of patches and workarounds for over a dozen vulnerabilities found across its industrial automation product line. These vulnerabilities impact several key products, including RSLinx Classic communications software, ControlLogix and CompactLogix controllers, and FactoryTalk applications. Among the most serious are four critical and high-severity denial-of-service vulnerabilities in RSLinx Classic that can crash the service, necessitating a restart to restore functionality.

The advisory also highlighted a high-severity denial-of-service vulnerability in the ControlLogix and CompactLogix controllers, identified as CVE-2026-9637. Interestingly, while the advisory initially indicated this vulnerability was exploited, further clarification revealed this was likely an oversight, and there is no evidence of exploitation according to both Rockwell and CISA.

Additional vulnerabilities addressed include issues in the FactoryTalk Historian Machine Edition, where a remote code execution flaw was fixed, and the FactoryTalk Activation Manager, which had a flaw that potentially allowed authenticated attackers to access files and system resources with elevated privileges. ArmorStart Distributed Motor Controllers received patches for multiple cross-site scripting vulnerabilities, and a denial-of-service issue affecting its web server.

The ControlFLASH firmware management utility had a vulnerability that could enable arbitrary code execution at the user's permission level, while a high-severity privilege escalation flaw was found in the Redundancy Module Configuration Tool. These updates are crucial to prevent potential exploitation that could disrupt operations or compromise system integrity.

Rockwell Automation's prompt action and detailed advisories are vital steps in maintaining the security and reliability of industrial control systems. Affected organizations are encouraged to apply the patches or workarounds as soon as possible to mitigate risks.