VORANT. Threat Intelligence Sign in Get the full feed

Rockwell 1718/1719-AENTR DoS flaw patched

low vulnerability manufacturing

A denial-of-service vulnerability in Rockwell Automation 1718-AENTR/1719-AENTR Ex I/O modules can be triggered by a UDP unicast network storm, requiring a power cycle to recover.

CISA published an ICS advisory for Rockwell Automation's 1718-AENTR/1719-AENTR Ex I/O modules, disclosing a denial-of-service vulnerability tracked as CVE-2026-9140. The flaw stems from improper handling of a UDP unicast network storm (CWE-770), which overloads the device and causes it to lose communication, requiring a manual power cycle to restore operation.

The issue affects version 3.011 of the 1718/1719 Ex I/O firmware and impacts critical manufacturing environments worldwide where Rockwell products are deployed. Rockwell Automation reported the vulnerability to CISA and has released version 3.012 to address the issue. No public exploitation has been reported at this time; CISA recommends standard ICS network isolation and segmentation practices for organizations unable to immediately patch.

Mentioned in this report

Vulnerabilities CVE-2026-9140

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free