# Rockwell Logix CIP Security Certificate Bypass Flaw

Published: 2026-07-30 · Severity: medium · Sectors: manufacturing
Canonical: https://vorant.io/reports/b8b2c203-1337-5333-b95f-9836180c9049/rockwell-logix-cip-security-certificate-bypass-flaw

> A CIP Security certificate revocation check failure in Rockwell CompactLogix/ControlLogix and 1756-EN4TR modules could let attackers bypass security using revoked certificates.

CISA published an advisory detailing CVE-2026-9636, affecting Rockwell Automation CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, Compact GuardLogix 5380 controllers (versions V36-V37), and the 1756-EN4TR communications module (V6.001, V7.001). The vulnerability arises from improper handling of Certificate Revocation Lists (CRLs) — the affected devices fail to reject certificates signed by an intermediate CA whose certificate has been revoked, potentially allowing a network-based attacker to establish an untrusted connection that should have been blocked by CIP Security controls.

Successful exploitation could allow an attacker to bypass CIP Security protections, potentially leading to a denial-of-service condition against critical manufacturing control systems. The products are deployed worldwide across critical manufacturing environments. Rockwell has released fixed firmware (V38.011 for the Logix controllers, V8.001 for the 1756-EN4TR module) and CISA recommends standard ICS network segmentation and isolation practices. No known public exploitation of this vulnerability has been reported at this time.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9636

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b8b2c203-1337-5333-b95f-9836180c9049/rockwell-logix-cip-security-certificate-bypass-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
