# Rockwell 1718/1719-AENTR DoS flaw patched

Published: 2026-07-21 · Severity: low · Sectors: manufacturing
Canonical: https://vorant.io/reports/de077aa0-f6c4-57e0-a3a7-f59cc54b497b/rockwell-1718-1719-aentr-dos-flaw-patched

> A denial-of-service vulnerability in Rockwell Automation 1718-AENTR/1719-AENTR Ex I/O modules can be triggered by a UDP unicast network storm, requiring a power cycle to recover.

CISA published an ICS advisory for Rockwell Automation's 1718-AENTR/1719-AENTR Ex I/O modules, disclosing a denial-of-service vulnerability tracked as CVE-2026-9140. The flaw stems from improper handling of a UDP unicast network storm (CWE-770), which overloads the device and causes it to lose communication, requiring a manual power cycle to restore operation.

The issue affects version 3.011 of the 1718/1719 Ex I/O firmware and impacts critical manufacturing environments worldwide where Rockwell products are deployed. Rockwell Automation reported the vulnerability to CISA and has released version 3.012 to address the issue. No public exploitation has been reported at this time; CISA recommends standard ICS network isolation and segmentation practices for organizations unable to immediately patch.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9140

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/de077aa0-f6c4-57e0-a3a7-f59cc54b497b/rockwell-1718-1719-aentr-dos-flaw-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
