# Rockwell Logix Controllers Vulnerable to DoS Flaw

Published: 2026-09-01 · Severity: routine · Sectors: manufacturing
Canonical: https://vorant.io/reports/ab38185e-f2b2-5c53-accb-e2e2ed52660d/rockwell-logix-controllers-vulnerable-to-dos-flaw

> A CIP message input validation flaw in Rockwell Automation Logix controllers can trigger a fault requiring manual power cycling to recover.

CISA and Rockwell Automation disclosed a denial-of-service vulnerability (CVE-2026-9637) affecting multiple Logix Platform product lines, including ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 across a range of firmware versions. The flaw stems from improper validation of input length during CIP (Common Industrial Protocol) message processing, which can result in a major nonrecoverable fault (MNRF) that halts controller operation and requires a physical power cycle to restore functionality. This affects critical manufacturing environments worldwide where these Rockwell controllers are deployed.

Rockwell has released corrected firmware versions (V37.011, 34.015, 35.014, and 36.013) addressing the issue, and recommends affected customers upgrade. For those unable to patch immediately, standard ICS security best practices are advised, including minimizing network exposure of control system devices, isolating control networks behind firewalls, and using secure remote access methods such as VPNs. CISA notes there is no known public exploitation of this vulnerability at this time, and it appears to be a defect discovered through vendor testing or coordinated disclosure rather than active attacker activity.

The vulnerability is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and could disrupt industrial operations if a malicious or malformed CIP message is sent to an affected controller, causing downtime until manual intervention. Given the safety and availability implications for manufacturing control systems, timely patching is recommended even absent evidence of in-the-wild exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9637

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ab38185e-f2b2-5c53-accb-e2e2ed52660d/rockwell-logix-controllers-vulnerable-to-dos-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
