# Thousands of Rockwell PLCs Vulnerable Online, Urgent Action Needed

*Published August 7, 2026*
*Source: [https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html](https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html)*

## Executive Summary

Forescout has identified over 4,400 internet-exposed Rockwell PLCs, raising concerns about the security of critical infrastructure. Specifically, 22 PLCs in cities recently attacked have been found vulnerable, emphasizing the need for immediate action to mitigate risks.

## Article

Forescout recently identified 4,407 Rockwell Automation programmable logic controllers (PLCs) exposed to the internet worldwide. This includes 2,844 located in the United States. Among these, 22 PLCs were found in cities that have recently experienced cyberattacks targeting water utilities. Nineteen of them are connected through the same mobile carrier network. This situation highlights the vulnerability of critical infrastructure components when left exposed online. Although no evidence of compromise was confirmed, the potential for malicious actors to exploit these PLCs is significant. Attackers have previously managed to disrupt operations by simply changing IP addresses and setting new passwords on accessible controllers, causing operators to lose control. This has been a particular concern for water and wastewater utilities in at least seven states, according to the FBI and EPA.

The exposure of EtherNet/IP on port 44818 is a critical issue because it provides an unauthenticated pathway that can allow attackers to identify or modify controller settings. More than 70 percent of the exposed controllers in the United States were found on large mobile carrier networks. The FBI and EPA have recommended implementing strong authentication measures, ensuring regular updates, and maintaining logging for cellular modems. Additionally, remote access should be isolated using a private APN, VPN, or a similar setup.

A snapshot from Censys on July 30 found 4,148 Rockwell/Allen-Bradley EtherNet/IP hosts exposed, with Verizon Business, AT&T Mobility, and T-Mobile USA making up 59 percent of the network exposure. While Forescout's data show a fluctuation in exposed devices, the overall number remains concerning. MicroLogix 1400 devices constitute 50 percent of the exposure and are vulnerable to CVE-2017-16740, a Modbus TCP buffer overflow flaw. Although Rockwell has addressed this in later firmware versions, exposure of PLCs directly to the internet remains a risky practice. Rockwell has also discontinued the MicroLogix 1100, providing guidance for resetting devices compromised by password changes. It is crucial for operators to maintain offline backups of controller logic to recover from potential attacks.
