highOther

Rockwell Automation Flex 5000 Adapter Double Free Denial-of-Service Vulnerability

First seen Jul 19, 2026 · Updated Jul 19, 2026 · CVSS 7.5

ICSOTdenial-of-serviceCISA-advisoryRockwell-AutomationCIP-protocoldouble-free

A high-severity denial-of-service vulnerability (CVE-2026-12659) affects Rockwell Automation Flex 5000 Adapter version 6.011 due to a double-free condition triggered by crafted CIP packets. Successful exploitation halts the affected module, requiring a manual power cycle to restore operation, posing operational risk to industrial control environments.

Technical Analysis

CVE-2026-12659 is a CWE-415 Double Free vulnerability in the Flex 5000 Adapter firmware where improper handling of exceptional conditions during CIP (Common Industrial Protocol) packet processing can be triggered remotely without authentication or user interaction. An attacker with network access to the adapter can send specially crafted CIP packets to cause memory corruption, resulting in a denial-of-service condition affecting the module and its associated I/O, requiring a physical power cycle to recover. CVSS 3.1 scores this 7.5 (High) and CVSS 4.0 scores 8.7 (High), reflecting the network-based, low-complexity, no-privilege exploitation path. This is a classic OT/ICS availability threat rather than a credential or data-theft vector, and there is no plausible direct impact to AI agent systems since this affects industrial I/O adapters rather than IT infrastructure, software supply chains, or agent hosting environments.

Affected Systems

Rockwell Automation Flex 5000 Adapter, firmware version 6.011; remediation available via upgrade to version 6.012

Indicators of Compromise

  • No known IOCs; no public exploitation reported at this time

Remediation Steps

  1. 1

    Upgrade Firmware

    Update Flex 5000 Adapter to version 6.012 or later as recommended by Rockwell Automation.

  2. 2

    Network Segmentation

    Isolate control system networks and devices behind firewalls, separating them from business/IT networks.

  3. 3

    Minimize Exposure

    Ensure control system devices, including the Flex 5000 Adapter, are not accessible from the internet.

  4. 4

    Secure Remote Access

    Use VPNs or other secure remote access methods when remote connectivity to ICS networks is required, keeping VPN software updated.

  5. 5

    Apply Vendor Best Practices

    Follow Rockwell Automation's security best practices and review Security Advisory SD1789 for additional mitigation guidance.

  6. 6

    Monitor and Report

    Monitor for anomalous CIP traffic and report suspected malicious activity to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2026-12659

Industries Most Exposed

Critical ManufacturingInformation TechnologyIndustrial Control Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.