Vendor
Privilege Escalation Vulnerability in Rockwell Automation FactoryTalk Activation Manager
1 rule 1 TTP 1 CVERockwell Automation FactoryTalk Activation Manager versions V5.02 and below are vulnerable to local privilege escalation via insecure installer custom actions that spawn SYSTEM-level console windows.
DLL Hijacking Vulnerabilities in Rockwell Automation Redundancy Module Configuration Tool
1 rule 1 TTP 2 CVEsRockwell Automation Redundancy Module Configuration Tool versions 9.x and 10.00.00 are vulnerable to DLL hijacking, potentially allowing local privilege escalation to SYSTEM level.
Denial-of-Service Vulnerability in Rockwell Automation Logix Platforms
1 CVERockwell Automation Logix controllers are vulnerable to a denial-of-service condition due to improper input length validation during CIP message processing, leading to major nonrecoverable faults.
Critical Vulnerabilities in Rockwell Automation Historian ME
2 TTPs 2 CVEsRockwell Automation Historian ME series B and C contain multiple vulnerabilities, including an out-of-bounds write allowing remote code execution and a buffer overflow causing denial-of-service.
Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic
1 TTP 4 CVEsMultiple vulnerabilities in Rockwell Automation RSLinx Classic allow an unauthenticated remote attacker to cause a denial-of-service condition via specially crafted CIP packets.
Insufficient Work Factor in Rockwell Automation OTTO Fleet Manager
1 CVERockwell Automation OTTO Fleet Manager versions V2.36.2 and earlier use an insufficient work factor for bcrypt password hashing, enabling attackers with access to system backups to perform efficient offline brute-force attacks.
Rockwell Automation Communication Modules Denial-of-Service Vulnerability
1 TTP 1 CVEA denial-of-service vulnerability (CVE-2026-9653) in Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules, due to improper validation of CIP Implicit Connection packets, allows an unauthenticated network attacker to continuously disrupt device connections.
Multiple Out-of-Bounds Write Vulnerabilities in Rockwell Automation Arena
1 rule 3 TTPs 4 CVEsMultiple out-of-bounds write vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in Rockwell Automation Arena versions prior to V17.00.01 could allow an attacker to execute arbitrary code by convincing a user to open a malicious file.
Rockwell Automation FactoryTalk DataMosaix Stored XSS Vulnerability (CVE-2026-9292)
2 TTPs 1 CVEAn authenticated attacker with high privileges can exploit CVE-2026-9292, a Stored Cross-Site Scripting (XSS) vulnerability, in Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier by injecting malicious scripts into the Workflows configuration, leading to execution of malicious JavaScript in other users' browsers and potential account takeover or credential theft.
Rockwell Automation Flex 5000 Adapter Vulnerability Leads to Denial of Service
2 TTPs 1 CVEA denial-of-service vulnerability (CVE-2026-12659), categorized as a Double Free issue (CWE-415), exists in Rockwell Automation Flex 5000 Adapter version 6.011 due to improper handling of crafted CIP packets, which could allow an unauthenticated attacker to cause a denial-of-service condition requiring a power cycle to recover.
Rockwell Automation CompactLogix and ControlLogix Vulnerabilities Lead to Denial-of-Service
2 TTPs 3 CVEsMultiple Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix product versions are vulnerable to denial-of-service conditions through CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, which an attacker can exploit via buffer overflows by loading invalid project files or writing invalid data, causing controllers to enter a major non-recoverable fault.
Rockwell Automation Studio 5000 Logix Designer: Multiple Vulnerabilities Enable Code Execution
1 TTPMultiple vulnerabilities in Rockwell Automation Studio 5000 Logix Designer allow a local attacker to execute arbitrary program code, which could lead to a compromise of the affected system or unauthorized control over the design environment.
Critical Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter (CVE-2026-10577)
1 TTP 1 CVEA critical unauthenticated remote access vulnerability, CVE-2026-10577, in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions <=3.003 allows an attacker to exploit a network-accessible debug port with missing privilege controls, enabling remote command-line interface access to read/delete files, modify memory, and change I/O states, impacting the confidentiality, integrity, and availability of industrial control systems.
Siemens Security Updates — July 2026
5 CVEs 2 IOCsRoundup of Siemens security advisories published in July 2026.
2026 FIFA World Cup: Cyber Threats and Attack Surface Analysis
2 rules 3 TTPsThe 2026 FIFA World Cup faces significant cyber threats from ransomware groups, state-aligned entities like Iran-nexus Handala Hack Team and Russia-nexus NoName057(16), and financially motivated cybercriminals, anticipating disruptive intrusions, large-scale criminal fraud, and politically driven DDoS and hack-and-leak operations targeting fans, hospitality services, and tournament infrastructure.