CISA Publishes Six Rockwell Advisories in a Single Day
Every advisory in the 1 September batch covers Rockwell products. The CVSS scores are unremarkable; the recovery procedures are not — several faults need a power cycle, a stage 2 reset or a program download.

CISA released six ICS advisories on 1 September 2026, numbered ICSA-26-244-01 through ICSA-26-244-06, and every one of them covers Rockwell Automation products. For a plant running Allen-Bradley equipment, that is an unusually concentrated patch event.
The lead advisory covers four flaws in RSLinx Classic version 4.50 and earlier — CVE-2026-9621, CVE-2026-9622, CVE-2026-9624 and CVE-2026-9625 — two rated CVSS v3.1 8.6 and two 7.5, all fixed in version 4.60. Each is triggered by a crafted CIP packet: a malformed packet, one targeting the Forward Close service, one that defeats insufficient data-length validation, and one carrying an oversized embedded message request. Each crashes the RSLinx Classic service until it is restarted.
ICSA-26-244-03 is the one to read first if you run Logix controllers. CVE-2026-9637, rated 7.5, is an input-length validation flaw in CIP message processing affecting ControlLogix 5580, CompactLogix 5380, GuardLogix 5580 and Compact GuardLogix 5380. Exploitation causes a major nonrecoverable fault, which is cleared by power-cycling the controller. Fixes are in firmware 34.015, 35.014, 36.013 and 37.011.
ICSA-26-244-05 re-issues the third-party flaw CVE-2021-42260 against the same controller families plus CompactLogix 5480. Recovery there is worse: a program download on safety controllers, a stage 2 reset on non-safety ones.
The remaining three cover software rather than controllers. ICSA-26-244-06 affects FactoryTalk Historian Machine Edition Series B 5.202 and Series C 7.101, where CVE-2025-12768 at CVSS 8.0 allows a low-privileged, network-adjacent attacker to achieve remote code execution, and CVE-2026-12661 is a buffer-overflow denial of service through the web interface. It is also the only advisory in the batch mapped beyond critical manufacturing, listing chemical, food and agriculture, healthcare and public health, and water and wastewater as deployment sectors. ICSA-26-244-04 covers CVE-2026-16675 in FactoryTalk Activation Manager V5.02 and earlier, where installer custom actions spawn visible console windows running as SYSTEM that an authenticated user can hijack; fixed in V5.03. ICSA-26-244-02 covers two DLL search-path flaws in the Redundancy Module Configuration Tool, neither remotely exploitable, fixed in 10.01.00.
CISA reports no known public exploitation of any of these, and repeats its standard guidance about keeping control systems off the internet and behind segregated firewalls.
The practical sting is not in the CVSS numbers. It is that the remedies are power cycles, stage 2 resets and program downloads on safety controllers — which is to say unplanned line stops, not background patching. The useful work this week is mapping firmware trains 34.015, 35.014, 36.013 and 37.011 against the controller inventory, so the patching lands in the next scheduled outage rather than needing one of its own.
Source: CISA