Rockwell Automation: CISA ICSA-26-244 batch (RSLinx Classic, Logix, FactoryTalk, more)
On 2 September 2026 CISA published a Rockwell Automation ICS advisory batch (ICSA-26-244-01 through ICSA-26-244-06) alongside Rockwell Trust Center advisories. ICSA-26-244-01 covers RSLinx Classic denial-of-service issues CVE-2026-9621, CVE-2026-9622, CVE-2026-9624 and CVE-2026-9625 (critical/high per SecurityWeek's read of the vendor set; exploitation can crash the RSLinx Classic service until restart). ICSA-26-244-03 covers Logix Platform CVE-2026-9637 (improper restriction of operations within memory buffer) with vendor CVSS 3.x 7.5 on ControlLogix 5580 and CompactLogix 5380 version ranges listed in the CISA advisory; CISA states it is not aware of public exploitation. SecurityWeek also notes FactoryTalk Historian RCE, FactoryTalk Activation Manager privilege issues, ArmorStart XSS/DoS, and ControlFLASH arbitrary code execution among the same Tuesday drop. Apply Rockwell patches or workarounds from the Trust Center; segment OT management hosts.
- Product
- Rockwell Automation RSLinx Classic, Logix Platform, FactoryTalk, ArmorStart, ControlFLASH
- Versions
- See ICSA-26-244-01..06 and Rockwell SD advisories; Logix CVE-2026-9637 lists ControlLogix 5580 and CompactLogix 5380 ranges in CISA text
- CVSS
- CVE-2026-9637 vendor CVSS 7.5 (CISA ICSA-26-244-03); RSLinx set critical/high per vendor/CISA batch — confirm each advisory
- Exploited in Australia?
- unknown
- Patch to
- Apply Rockwell patches/workarounds for ICSA-26-244-01..06; restart RSLinx after DoS; segment OT engineering hosts
Primary: CISA ICSA-26-244-01 (RSLinx Classic, 2 Sep 2026) · Vendor: Rockwell Automation Trust Center advisories · CVE: CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-9637 · SecurityWeek (2 Sep 2026)
