Rockwell Flex 5000 Adapter DoS Flaw Patched
A denial-of-service vulnerability in Rockwell Automation's Flex 5000 Adapter can be triggered by crafted CIP packets, requiring a power cycle to recover.
CISA has published an advisory for a vulnerability affecting Rockwell Automation's Flex 5000 Adapter version 6.011, used in industrial control system environments within the Critical Manufacturing and Information Technology sectors worldwide. The flaw, tracked as CVE-2026-12659, stems from improper handling of exceptional conditions when the adapter processes specially crafted CIP (Common Industrial Protocol) packets, resulting in a denial-of-service condition. Affected devices require a manual power cycle to restore the module and its associated I/O, meaning exploitation could cause operational disruption in industrial settings until physical intervention occurs.
Rockwell Automation has released a fix in version 6.012 and recommends affected customers upgrade. For those unable to immediately patch, the vendor and CISA recommend applying standard ICS security best practices, including minimizing network exposure, isolating control system networks behind firewalls, and using secure remote access methods such as VPNs. CISA notes no known public exploitation targeting this vulnerability has been reported at this time.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-08
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free