Rockwell 1718/1719-AENTR DoS flaw patched
A denial-of-service vulnerability in Rockwell Automation 1718-AENTR/1719-AENTR Ex I/O modules can be triggered by a UDP unicast network storm, requiring a power cycle to recover.
CISA published an ICS advisory for Rockwell Automation's 1718-AENTR/1719-AENTR Ex I/O modules, disclosing a denial-of-service vulnerability tracked as CVE-2026-9140. The flaw stems from improper handling of a UDP unicast network storm (CWE-770), which overloads the device and causes it to lose communication, requiring a manual power cycle to restore operation.
The issue affects version 3.011 of the 1718/1719 Ex I/O firmware and impacts critical manufacturing environments worldwide where Rockwell products are deployed. Rockwell Automation reported the vulnerability to CISA and has released version 3.012 to address the issue. No public exploitation has been reported at this time; CISA recommends standard ICS network isolation and segmentation practices for organizations unable to immediately patch.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free