Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-9621
Rockwell Automation RSLinx Classic vulnerability analysis and mitigation

Overview

CVE-2026-9621 is a denial-of-service vulnerability in Rockwell Automation RSLinx® Classic that allows unauthenticated remote attackers to crash the service by sending a crafted Common Industrial Protocol (CIP) packet. The root cause is improper handling of malformed packets, classified as an Integer Overflow or Wraparound (CWE-190). Affected versions include RSLinx Classic V4.50 and prior. The vulnerability was published on September 1, 2026, with a patch made available the same day. It carries a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, Rockwell Advisory).

Technical details

The vulnerability stems from an integer overflow or wraparound condition (CWE-190) in RSLinx Classic's CIP packet parsing logic, which can be triggered by a specially crafted malformed packet. When the service processes the malformed CIP packet, the integer overflow causes improper memory handling, leading to a service crash. No authentication or user interaction is required, and there are no special attack prerequisites — the service only needs to be reachable over the network. This maps to CAPEC-92 (Forced Integer Overflow). Feedly's CWE estimate also suggests a potential out-of-bounds write (CWE-787) as a secondary consequence of the overflow (GitHub Advisory, Rockwell Advisory).

Impact

Successful exploitation causes the RSLinx Classic service to crash, rendering it unavailable until manually restarted. RSLinx Classic is widely used in industrial environments as a communication server bridging Rockwell Automation PLCs and SCADA/HMI systems, so a service outage can disrupt industrial operations, monitoring, and control functions. There is no evidence of confidentiality or integrity impact — the vulnerability is limited to availability. In OT/ICS environments, repeated or timed attacks could cause sustained operational disruptions (GitHub Advisory, CISA ICS Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability is rated as automatable by NVD SSVC, meaning it can be exploited without human interaction at scale. The EPSS score is approximately 0.31% (24th percentile), indicating a relatively low near-term exploitation probability. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (CISA ICS Advisory).

Exploitation steps

  1. Reconnaissance: Identify RSLinx Classic instances exposed on the network using tools such as Shodan or Nmap, scanning for CIP/EtherNet/IP services (typically TCP/UDP port 44818 or 2222).
  2. Confirm target version: Verify the target is running RSLinx Classic V4.50 or prior, which is vulnerable.
  3. Craft malformed CIP packet: Construct a CIP packet with a malformed or oversized field designed to trigger an integer overflow in the packet parsing routine.
  4. Send the packet: Transmit the crafted packet to the RSLinx Classic service over the network — no authentication or prior session establishment is required.
  5. Trigger crash: The integer overflow causes the RSLinx Classic service to crash, making it unavailable until an operator manually restarts it (GitHub Advisory, Rockwell Advisory).

Indicators of compromise

  • Network: Unexpected or malformed CIP packets (EtherNet/IP) arriving on TCP/UDP port 44818 or 2222 from unauthorized or external IP addresses; repeated connection attempts to RSLinx Classic from unknown sources.
  • Logs: Windows Event Log entries showing the RSLinx Classic service (RSLinx.exe) terminating unexpectedly or with a non-zero exit code; application crash logs or Windows Error Reporting entries referencing RSLinx Classic.
  • Process: Sudden absence of the RSLinx Classic process from the process list; automated or manual service restart events logged in the Windows System Event Log.
  • File System: Crash dump files (.dmp) generated in the RSLinx Classic installation directory or Windows crash dump locations following unexpected termination.

Mitigation and workarounds

Rockwell Automation has released a patch for this vulnerability, available via the official security advisory SD1794. Users should upgrade RSLinx Classic to a version beyond V4.50 as directed by the advisory. As a network-level workaround, restrict CIP protocol traffic (TCP/UDP port 44818 and 2222) to only authorized systems using firewalls or industrial DMZ architectures. Additionally, monitor RSLinx Classic service availability and configure automated alerting for unexpected service crashes to enable rapid response (Rockwell Advisory, GitHub Advisory, CISA ICS Advisory).

Community reactions

The vulnerability was covered in The Hacker News' weekly recap for September 2026, which highlighted it among notable ICS vulnerabilities (The Hacker News). CISA published an ICS advisory (ICSA-26-244-01) on the same day as disclosure, underscoring the relevance of the vulnerability to critical infrastructure operators (CISA ICS Advisory). Security aggregators including Tenable (Nessus plugin 342353) and AusCERT also published coverage shortly after disclosure (Tenable).

Additional resources


SourceThis report was generated using AI

Related Rockwell Automation RSLinx Classic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9621CRITICAL9.2
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9625HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9624HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9622HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2020-13573HIGH7.5
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx:*:*:*:*:classic:*:*:*
NoYesJan 07, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management