Rockwell Automation ArmorStart LT Stored XSS and Denial-of-Service Vulnerabilities
First seen Sep 6, 2026 · Updated Sep 6, 2026 · CVSS 7.5
Rockwell Automation ArmorStart LT firmware versions ≤v2.001 contain two vulnerabilities: a stored cross-site scripting flaw and a denial-of-service issue triggered by a crafted HTTP PUT request to the embedded web server. Exploitation could allow an attacker to inject malicious scripts executed by other users or crash the device's web server, disrupting availability. No public exploitation has been reported, and Rockwell has released firmware v2.002 to remediate both issues.
Technical Analysis
CVE-2026-19471 (CWE-79) is a stored XSS vulnerability in ArmorStart LT's web interface, allowing unsanitized user input to be persisted and executed in other users' browser sessions (CVSS v3.1 7.3). CVE-2026-19472 (CWE-770) stems from improper resource throttling when handling crafted HTTP PUT requests, enabling a remote unauthenticated attacker to cause denial of service against the embedded web server (CVSS v3.1 7.5, CVSS v4.0 8.7). Both vulnerabilities are remotely exploitable over the network with low attack complexity and no privileges or user interaction required for the DoS vector. This is an industrial control system (ArmorStart LT is a motor controller/starter used in critical manufacturing) rather than an IT/AI system, so there is no direct impact to AI agent frameworks, LLM tool use, or RAG pipelines; however, organizations using AI-driven OT monitoring or agentic automation to manage ICS device fleets should ensure such agents do not have unmediated write access to the affected web interfaces, as a compromised or DoS'd device could disrupt automated decision loops relying on its telemetry.
Affected Systems
Rockwell Automation ArmorStart LT firmware versions <=v2.001; corrected in firmware v2.002
Indicators of Compromise
- No known IOCs published; no public exploitation reported at time of advisory (2026-09-03)
Remediation Steps
- 1
Update Firmware
Upgrade ArmorStart LT devices to firmware version v2.002 or later, which corrects both the stored XSS and DoS vulnerabilities.
- 2
Network Segmentation
Isolate control system networks and devices from business/IT networks and ensure they are not directly accessible from the internet.
- 3
Secure Remote Access
Use VPNs or other secure remote access methods when remote connectivity is required, and keep VPN software updated.
- 4
Apply Vendor Best Practices
Follow Rockwell Automation's published security best practices for devices that cannot be immediately updated.
- 5
Monitor and Report
Monitor for suspicious activity targeting ICS web interfaces and report findings to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.