Skip to content
Threat Feed

Vendor

Rockwell Automation

15 briefs RSS
high advisory

Privilege Escalation Vulnerability in Rockwell Automation FactoryTalk Activation Manager

Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below are vulnerable to local privilege escalation via insecure installer custom actions that spawn SYSTEM-level console windows.

FactoryTalk Activation Manager privilege-escalation industrial-control-systems windows ics
1r 1t 1c
high advisory

DLL Hijacking Vulnerabilities in Rockwell Automation Redundancy Module Configuration Tool

Rockwell Automation Redundancy Module Configuration Tool versions 9.x and 10.00.00 are vulnerable to DLL hijacking, potentially allowing local privilege escalation to SYSTEM level.

Redundancy Module Configuration Tool +1 privilege-escalation dll-hijacking industrial-control-systems windows
1r 1t 2c
high threat

Denial-of-Service Vulnerability in Rockwell Automation Logix Platforms

Rockwell Automation Logix controllers are vulnerable to a denial-of-service condition due to improper input length validation during CIP message processing, leading to major nonrecoverable faults.

exploited ControlLogix 5580 +3 industrial-control-systems denial-of-service cve-2026-9637 ot-security
1c
high advisory

Critical Vulnerabilities in Rockwell Automation Historian ME

Rockwell Automation Historian ME series B and C contain multiple vulnerabilities, including an out-of-bounds write allowing remote code execution and a buffer overflow causing denial-of-service.

Historian ME +1
2t 2c
medium advisory

Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic

Multiple vulnerabilities in Rockwell Automation RSLinx Classic allow an unauthenticated remote attacker to cause a denial-of-service condition via specially crafted CIP packets.

RSLinx Classic ics ot denial-of-service vulnerability
1t 4c
medium advisory

Insufficient Work Factor in Rockwell Automation OTTO Fleet Manager

Rockwell Automation OTTO Fleet Manager versions V2.36.2 and earlier use an insufficient work factor for bcrypt password hashing, enabling attackers with access to system backups to perform efficient offline brute-force attacks.

OTTO Fleet Manager
1c
medium advisory

Rockwell Automation Communication Modules Denial-of-Service Vulnerability

A denial-of-service vulnerability (CVE-2026-9653) in Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules, due to improper validation of CIP Implicit Connection packets, allows an unauthenticated network attacker to continuously disrupt device connections.

1756-EN2 <=V12.001 +2 industrial-control-systems ics ot vulnerability denial-of-service rockwell-automation
1t 1c
high advisory

Multiple Out-of-Bounds Write Vulnerabilities in Rockwell Automation Arena

Multiple out-of-bounds write vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in Rockwell Automation Arena versions prior to V17.00.01 could allow an attacker to execute arbitrary code by convincing a user to open a malicious file.

Rockwell Automation Arena <=V17.00.00 +1 vulnerability ics ot memory-corruption out-of-bounds-write arbitrary-code-execution critical-manufacturing
1r 3t 4c updated
high advisory

Rockwell Automation FactoryTalk DataMosaix Stored XSS Vulnerability (CVE-2026-9292)

An authenticated attacker with high privileges can exploit CVE-2026-9292, a Stored Cross-Site Scripting (XSS) vulnerability, in Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier by injecting malicious scripts into the Workflows configuration, leading to execution of malicious JavaScript in other users' browsers and potential account takeover or credential theft.

FactoryTalk DataMosaix Private Cloud xss ics ot vulnerability cve
2t 1c
medium advisory

Rockwell Automation Flex 5000 Adapter Vulnerability Leads to Denial of Service

A denial-of-service vulnerability (CVE-2026-12659), categorized as a Double Free issue (CWE-415), exists in Rockwell Automation Flex 5000 Adapter version 6.011 due to improper handling of crafted CIP packets, which could allow an unauthenticated attacker to cause a denial-of-service condition requiring a power cycle to recover.

Flex 5000 Adapter ics ot critical-manufacturing information-technology denial-of-service vulnerability
2t 1c
medium advisory

Rockwell Automation CompactLogix and ControlLogix Vulnerabilities Lead to Denial-of-Service

Multiple Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix product versions are vulnerable to denial-of-service conditions through CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, which an attacker can exploit via buffer overflows by loading invalid project files or writing invalid data, causing controllers to enter a major non-recoverable fault.

CompactLogix 5370 +13 ics scada denial-of-service critical-manufacturing vulnerability
2t 3c
medium advisory

Rockwell Automation Studio 5000 Logix Designer: Multiple Vulnerabilities Enable Code Execution

Multiple vulnerabilities in Rockwell Automation Studio 5000 Logix Designer allow a local attacker to execute arbitrary program code, which could lead to a compromise of the affected system or unauthorized control over the design environment.

Studio 5000 Logix Designer ics scada ot rce vulnerability local-exploitation
1t
medium advisory

Critical Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter (CVE-2026-10577)

A critical unauthenticated remote access vulnerability, CVE-2026-10577, in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions <=3.003 allows an attacker to exploit a network-accessible debug port with missing privilege controls, enabling remote command-line interface access to read/delete files, modify memory, and change I/O states, impacting the confidentiality, integrity, and availability of industrial control systems.

1715-AENTR EtherNet/IP Adapter <=3.003 ics ot vulnerability critical-infrastructure remote-code-execution
1t 1c
high advisory

Siemens Security Updates — July 2026

Roundup of Siemens security advisories published in July 2026.

PoC CPCI85 Central Processing/Communication < V26.20 +27 roundup
5c 2i updated
high threat

2026 FIFA World Cup: Cyber Threats and Attack Surface Analysis

The 2026 FIFA World Cup faces significant cyber threats from ransomware groups, state-aligned entities like Iran-nexus Handala Hack Team and Russia-nexus NoName057(16), and financially motivated cybercriminals, anticipating disruptive intrusions, large-scale criminal fraud, and politically driven DDoS and hack-and-leak operations targeting fans, hospitality services, and tournament infrastructure.

programmable logic controllers +5 Handala Hack Team 2026 World Cup cybersecurity threat intelligence ransomware DDoS phishing
2r 3t