Rockwell Automation Flex 5000 Adapter Double Free Denial-of-Service Vulnerability
First seen Jul 19, 2026 · Updated Jul 19, 2026 · CVSS 7.5
A high-severity denial-of-service vulnerability (CVE-2026-12659) affects Rockwell Automation Flex 5000 Adapter version 6.011 due to a double-free condition triggered by crafted CIP packets. Successful exploitation halts the affected module, requiring a manual power cycle to restore operation, posing operational risk to industrial control environments.
Technical Analysis
CVE-2026-12659 is a CWE-415 Double Free vulnerability in the Flex 5000 Adapter firmware where improper handling of exceptional conditions during CIP (Common Industrial Protocol) packet processing can be triggered remotely without authentication or user interaction. An attacker with network access to the adapter can send specially crafted CIP packets to cause memory corruption, resulting in a denial-of-service condition affecting the module and its associated I/O, requiring a physical power cycle to recover. CVSS 3.1 scores this 7.5 (High) and CVSS 4.0 scores 8.7 (High), reflecting the network-based, low-complexity, no-privilege exploitation path. This is a classic OT/ICS availability threat rather than a credential or data-theft vector, and there is no plausible direct impact to AI agent systems since this affects industrial I/O adapters rather than IT infrastructure, software supply chains, or agent hosting environments.
Affected Systems
Rockwell Automation Flex 5000 Adapter, firmware version 6.011; remediation available via upgrade to version 6.012
Indicators of Compromise
- No known IOCs; no public exploitation reported at this time
Remediation Steps
- 1
Upgrade Firmware
Update Flex 5000 Adapter to version 6.012 or later as recommended by Rockwell Automation.
- 2
Network Segmentation
Isolate control system networks and devices behind firewalls, separating them from business/IT networks.
- 3
Minimize Exposure
Ensure control system devices, including the Flex 5000 Adapter, are not accessible from the internet.
- 4
Secure Remote Access
Use VPNs or other secure remote access methods when remote connectivity to ICS networks is required, keeping VPN software updated.
- 5
Apply Vendor Best Practices
Follow Rockwell Automation's security best practices and review Security Advisory SD1789 for additional mitigation guidance.
- 6
Monitor and Report
Monitor for anomalous CIP traffic and report suspected malicious activity to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.