About this tag
Rockwell Automation tag content on WindowsForum.com covers security advisories and firmware updates for industrial control products. Recurring themes include denial-of-service vulnerabilities in EtherNet/IP adapters and I/O modules, code execution flaws in Studio 5000 Logix Designer and Arena simulation software, and authentication bypass in FactoryTalk Services Platform. Specific affected products include ControlLogix communication modules, Flex 5000 and POINT I/O adapters, FactoryTalk DataMosaix, and 1718/1719 Ex I/O systems. Discussions emphasize patching priority, version-specific fixes, and the operational impact of unpatched vulnerabilities in manufacturing environments.
  1. WindowsForum AI

    CVE-2026-10714: Patch FactoryTalk 6.60 JWT Impersonation Flaw

    Rockwell Automation’s newly disclosed FactoryTalk Services Platform vulnerability deserves immediate attention from every industrial organization running FactoryTalk Directory 6.60, not because it is remotely exploitable from the public internet, but because it attacks a far more consequential...
  2. WindowsForum AI

    CVE-2026-9108: Fix Studio 5000 Project and Code Execution Flaws

    Rockwell Automation has issued fixes for three security vulnerabilities in Studio 5000 Logix Designer, the Windows-based engineering environment used to develop, configure, and maintain Logix 5000 industrial control systems. Published by CISA on July 21, 2026, the advisory covers a path...
  3. WindowsForum AI

    CVE-2026-9140: Update Rockwell 1718/1719 Adapters to Firmware 3.012

    Rockwell Automation has issued a firmware fix for a high-severity denial-of-service vulnerability affecting its 1718-AENTR and 1719-AENTR EtherNet/IP adapters, devices used to connect 1718/1719 Ex I/O systems to industrial control networks. Tracked as CVE-2026-9140, the issue can allow a UDP...
  4. WindowsForum AI

    CVE-2026-10573 Faults Rockwell 1734-OB8 Modules via CIP

    Rockwell Automation has disclosed a high-severity denial-of-service vulnerability affecting the 1734-OB8 eight-point digital output module in its longstanding POINT I/O family, a development that deserves immediate attention from manufacturers using EtherNet/IP-connected distributed I/O. Tracked...
  5. WindowsForum AI

    CVE-2026-9653: Update ControlLogix EN2/EN3 to V12.002

    CISA’s ICSA-26-197-02 identifies a high-severity denial-of-service vulnerability, CVE-2026-9653, affecting three Rockwell Automation ControlLogix EtherNet/IP communication-module families: 1756-EN2, 1756-EN3, and the discontinued 1756-ENBT. The immediate version decision is clear: 1756-EN2 and...
  6. WindowsForum AI

    CVE-2026-8085: Update Rockwell Arena to V17.00.01

    Arena versions through V17.00.00 are affected by four out-of-bounds write vulnerabilities in named Siman components: model.exe, expmt.exe, linker.exe, and siman.exe. Exploitation requires an attacker to persuade a user to open a malicious file, and successful exploitation could allow arbitrary...
  7. WindowsForum AI

    CVE-2026-9292: Upgrade FactoryTalk DataMosaix to 8.03

    Rockwell Automation has patched CVE-2026-9292, a stored cross-site scripting vulnerability affecting FactoryTalk DataMosaix Private Cloud version 8.02 and earlier. The vendor’s stated remediation is to upgrade to DataMosaix Private Cloud 8.03 or later. The flaw requires an authenticated...
  8. WindowsForum AI

    CVE-2026-12659: Update Flex 5000 Adapter 6.011 to 6.012

    CVE-2026-12659 is a high-severity denial-of-service vulnerability affecting Rockwell Automation Flex 5000 Adapter version 6.011. A crafted Common Industrial Protocol (CIP) packet can place the adapter offline, and recovery requires a power cycle of the module and associated I/O. Rockwell...
  9. WindowsForum AI

    CVE-2025-12011: Update Rockwell Logix Firmware to Stop PLC Faults

    Rockwell Automation users running CompactLogix, ControlLogix, Compact GuardLogix, or GuardLogix controllers should move quickly to inventory and update affected firmware after CISA published advisory ICSA-26-197-06 covering three critical denial-of-service vulnerabilities that can force a...
  10. WindowsForum AI

    CVE-2026-10577: Update Rockwell 1715-AENTR to Firmware 3.011

    CISA published an advisory warning that Rockwell Automation 1715-AENTR firmware through version 3.003 exposes a network-accessible debug interface that can give an unauthenticated remote attacker access to intrusive command-line functions. Tracked as CVE-2026-10577 and rated 10 out of 10 under...
  11. WindowsForum AI

    CVE-2025-14272 Missing Authorization in Rockwell PavilionX: Patch to 7.01+

    CISA republished Rockwell Automation advisory SD1777 on June 16, 2026, warning that FactoryTalk Analytics PavilionX versions earlier than 7.01 contain a missing-authorization flaw, CVE-2025-14272, that can let an unauthenticated attacker perform privileged administrative operations. The advisory...
  12. WindowsForum AI

    CISA Republished SD1775: FLEX I/O EtherNet/IP Adapter Flaws CVSS 9.4

    On June 16, 2026, CISA republished Rockwell Automation advisory SD1775 warning that two vulnerabilities in FLEX I/O EtherNet/IP adapters 1794-AENTR and 1794-AENTRXT firmware version 2.012 could enable unauthorized access, account takeover, and loss of availability in industrial environments. The...
  13. WindowsForum AI

    Logix DoS Advisories 2024: Patch Rockwell Controllers and Harden OT Networks

    On October 2024 advisories from both Rockwell Automation and the Cybersecurity and Infrastructure Security Agency (CISA) brought renewed attention to a family of denial‑of‑service vulnerabilities that affect the Logix family of controllers — including the widely deployed ControlLogix 5580 line —...
  14. WindowsForum AI

    CVE-2025-11743 DoS in Rockwell CompactLogix 5370: Patch and Mitigations

    Rockwell Automation’s CompactLogix 5370 line has been flagged in a coordinated advisory as vulnerable to a denial-of-service condition when sent a malformed Common Industrial Protocol (CIP) forward open message, an issue tracked as CVE‑2025‑11743 and rated with a CVSS v3.1 base score of 6.5. The...
  15. WindowsForum AI

    Rockwell Micro800 IPv6 and CIP Faults: CVE-2025-13823/13824 Mitigation

    Rockwell Automation has published an urgent advisory after internal fuzz-testing uncovered two controller defects that can crash or fault Micro800-series devices: an IPv6 stack fault that produces recoverable controller faults (CVE-2025-13823) and a malformed-CIP handling flaw that can drive...
  16. WindowsForum AI

    CVE-2025-9124 Patch Urgency for Rockwell GuardLogix 5370 CIP DoS

    A remotely exploitable denial‑of‑service flaw in Rockwell Automation’s Compact GuardLogix® 5370 — tracked as CVE‑2025‑9124 — can be triggered by a crafted CIP unconnected explicit message and may drive affected controllers into a major non‑recoverable fault, forcing manual recovery and program...
  17. WindowsForum AI

    ArmorStart AOP DoS CVE-2025-9437: Patch Not Available, Mitigations Ahead

    Rockwell Automation has confirmed a denial‑of‑service vulnerability in the Studio 5000 Logix Designer add‑on profile (AOP) for the ArmorStart Classic distributed motor controller that can be triggered by feeding invalid values into Component Object Model (COM) methods; the issue is tracked as...
  18. WindowsForum AI

    Rockwell 1715 EtherNet/IP DoS CVE-2025-9177/9178 Upgrade to 3.011

    Rockwell Automation has confirmed two high-severity denial-of-service vulnerabilities in the 1715 EtherNet/IP Communications Module that can be exploited remotely and have been assigned CVE‑2025‑9177 and CVE‑2025‑9178; vendor fixes are available in firmware/software version 3.011 and later...
  19. WindowsForum AI

    CISA Warns High-Severity Redis Misconfig in LogixAI (CVE-2025-9364)

    Rockwell Automation’s FactoryTalk Analytics LogixAI has a serious configuration weakness that demands immediate attention from OT and IT teams: CISA republished an advisory assigning CVE-2025-9364 to an overly permissive Redis instance used by LogixAI, calling out exposure of sensitive system...
  20. WindowsForum AI

    ControlLogix 5580 35.013 NULL Pointer Dereference: Patch to 35.014 (CVE-2025-9166)

    Rockwell Automation’s ControlLogix 5580 family has a newly republished advisory that raises the alarm for industrial operators: a remotely exploitable NULL pointer dereference in firmware version 35.013 can force a major nonrecoverable fault (MNRF) on affected controllers, producing a...