Rockwell Logix CIP Security Certificate Bypass Flaw
A CIP Security certificate revocation check failure in Rockwell CompactLogix/ControlLogix and 1756-EN4TR modules could let attackers bypass security using revoked certificates.
CISA published an advisory detailing CVE-2026-9636, affecting Rockwell Automation CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, Compact GuardLogix 5380 controllers (versions V36-V37), and the 1756-EN4TR communications module (V6.001, V7.001). The vulnerability arises from improper handling of Certificate Revocation Lists (CRLs) — the affected devices fail to reject certificates signed by an intermediate CA whose certificate has been revoked, potentially allowing a network-based attacker to establish an untrusted connection that should have been blocked by CIP Security controls.
Successful exploitation could allow an attacker to bypass CIP Security protections, potentially leading to a denial-of-service condition against critical manufacturing control systems. The products are deployed worldwide across critical manufacturing environments. Rockwell has released fixed firmware (V38.011 for the Logix controllers, V8.001 for the 1756-EN4TR module) and CISA recommends standard ICS network segmentation and isolation practices. No known public exploitation of this vulnerability has been reported at this time.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free