highOther

Rockwell Automation Logix Platform CIP Message Denial-of-Service Vulnerability (CVE-2026-9637)

First seen Sep 3, 2026 · Updated Sep 3, 2026 · CVSS 7.5

ICSOTdenial-of-serviceRockwell-AutomationLogixCIP-protocolcritical-manufacturingmemory-corruption

A high-severity denial-of-service vulnerability affects multiple Rockwell Automation Logix Platform controllers due to improper input length validation during CIP message processing. Successful exploitation causes a major nonrecoverable fault (MNRF), requiring a physical power cycle to restore operations. No public exploitation has been observed at this time.

Technical Analysis

CVE-2026-9637 is rooted in CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), triggered when malformed or oversized Common Industrial Protocol (CIP) messages are processed by affected Logix controllers. This can cause a major nonrecoverable fault (MNRF), rendering the controller inoperable until a manual power cycle is performed, resulting in a network-exploitable, low-complexity, unauthenticated denial-of-service condition (CVSS 3.1: 7.5 HIGH; CVSS 4.0: 8.7 HIGH). The vulnerability affects ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 platforms across multiple firmware version ranges. This is an OT/ICS-specific flaw with no direct AI agent code execution or data exposure vector; however, organizations running AI-driven industrial monitoring, predictive maintenance, or autonomous control-loop agents that interface with these PLCs via CIP could experience agent task failures, stale sensor data, or unsafe automated decision-making if the underlying controller faults unexpectedly, warranting inclusion of these systems in agent-integrated OT environments' risk assessments.

Affected Systems

Rockwell Automation ControlLogix 5580 (<=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012); CompactLogix 5380 (same version ranges); GuardLogix 5580 (same version ranges); Compact GuardLogix 5380 (same version ranges)

Indicators of Compromise

  • No known IOCs published; no public exploitation reported at this time.

Remediation Steps

  1. 1

    Apply Vendor Firmware Updates

    Update ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 to firmware V37.011, 34.015, 35.014, or 36.013 depending on current version branch.

  2. 2

    Network Segmentation

    Isolate control system networks and devices behind firewalls, separating them from business/IT networks and the internet.

  3. 3

    Restrict Remote Access

    Use secure, updated VPN solutions for any required remote access to ICS/OT environments, and minimize network exposure of control system devices.

  4. 4

    Apply Rockwell Security Best Practices

    For systems that cannot be immediately updated, implement Rockwell Automation's published security hardening and best practice guidance.

  5. 5

    Monitor and Report

    Monitor for anomalous CIP traffic and unexpected MNRF events; report suspected malicious activity to CISA for correlation and tracking.

CVE / Advisory IDs

CVE-2026-9637

Industries Most Exposed

Critical ManufacturingIndustrial AutomationEnergyWater and WastewaterAny sector using Rockwell Logix PLCs

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.