Rockwell ArmorStart LT XSS and DoS flaws patched
CISA advisory details stored XSS and denial-of-service vulnerabilities in Rockwell Automation ArmorStart LT firmware, fixed in v2.002.
CISA published an ICS advisory covering two vulnerabilities in Rockwell Automation's ArmorStart LT product, used in the Critical Manufacturing sector worldwide. CVE-2026-19471 is a stored cross-site scripting issue caused by improper sanitization of user input, allowing an attacker to inject malicious scripts that execute when other users view the affected web page. CVE-2026-19472 is a denial-of-service vulnerability triggered by a crafted HTTP PUT request sent to the device's embedded web server, which can cause loss of web server availability due to improper resource allocation and throttling.
Both vulnerabilities affect ArmorStart LT firmware versions v2.001 and earlier. Rockwell Automation has released firmware v2.002 to remediate both issues and recommends all users upgrade. For organizations unable to patch immediately, Rockwell and CISA recommend standard ICS security best practices, including minimizing network exposure, isolating control system networks behind firewalls, and using secure remote access methods such as VPNs.
CISA states no known public exploitation targeting these vulnerabilities has been reported at this time. The advisory was initially released on 2026-09-03, with the vulnerabilities reported to CISA by Rockwell Automation itself.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free