highOther

Rockwell Automation ArmorStart LT Stored XSS and Denial-of-Service Vulnerabilities

First seen Sep 6, 2026 · Updated Sep 6, 2026 · CVSS 7.5

ICSOTcritical-infrastructurerockwell-automationcross-site-scriptingdenial-of-servicecisa-advisory

Rockwell Automation ArmorStart LT firmware versions ≤v2.001 contain two vulnerabilities: a stored cross-site scripting flaw and a denial-of-service issue triggered by a crafted HTTP PUT request to the embedded web server. Exploitation could allow an attacker to inject malicious scripts executed by other users or crash the device's web server, disrupting availability. No public exploitation has been reported, and Rockwell has released firmware v2.002 to remediate both issues.

Technical Analysis

CVE-2026-19471 (CWE-79) is a stored XSS vulnerability in ArmorStart LT's web interface, allowing unsanitized user input to be persisted and executed in other users' browser sessions (CVSS v3.1 7.3). CVE-2026-19472 (CWE-770) stems from improper resource throttling when handling crafted HTTP PUT requests, enabling a remote unauthenticated attacker to cause denial of service against the embedded web server (CVSS v3.1 7.5, CVSS v4.0 8.7). Both vulnerabilities are remotely exploitable over the network with low attack complexity and no privileges or user interaction required for the DoS vector. This is an industrial control system (ArmorStart LT is a motor controller/starter used in critical manufacturing) rather than an IT/AI system, so there is no direct impact to AI agent frameworks, LLM tool use, or RAG pipelines; however, organizations using AI-driven OT monitoring or agentic automation to manage ICS device fleets should ensure such agents do not have unmediated write access to the affected web interfaces, as a compromised or DoS'd device could disrupt automated decision loops relying on its telemetry.

Affected Systems

Rockwell Automation ArmorStart LT firmware versions <=v2.001; corrected in firmware v2.002

Indicators of Compromise

  • No known IOCs published; no public exploitation reported at time of advisory (2026-09-03)

Remediation Steps

  1. 1

    Update Firmware

    Upgrade ArmorStart LT devices to firmware version v2.002 or later, which corrects both the stored XSS and DoS vulnerabilities.

  2. 2

    Network Segmentation

    Isolate control system networks and devices from business/IT networks and ensure they are not directly accessible from the internet.

  3. 3

    Secure Remote Access

    Use VPNs or other secure remote access methods when remote connectivity is required, and keep VPN software updated.

  4. 4

    Apply Vendor Best Practices

    Follow Rockwell Automation's published security best practices for devices that cannot be immediately updated.

  5. 5

    Monitor and Report

    Monitor for suspicious activity targeting ICS web interfaces and report findings to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2026-19471CVE-2026-19472

Industries Most Exposed

Critical ManufacturingIndustrial Control SystemsOperational Technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.