
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-9621 is a denial-of-service vulnerability in Rockwell Automation RSLinx® Classic that allows unauthenticated remote attackers to crash the service by sending a crafted Common Industrial Protocol (CIP) packet. The root cause is improper handling of malformed packets, classified as an Integer Overflow or Wraparound (CWE-190). Affected versions include RSLinx Classic V4.50 and prior. The vulnerability was published on September 1, 2026, with a patch made available the same day. It carries a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, Rockwell Advisory).
The vulnerability stems from an integer overflow or wraparound condition (CWE-190) in RSLinx Classic's CIP packet parsing logic, which can be triggered by a specially crafted malformed packet. When the service processes the malformed CIP packet, the integer overflow causes improper memory handling, leading to a service crash. No authentication or user interaction is required, and there are no special attack prerequisites — the service only needs to be reachable over the network. This maps to CAPEC-92 (Forced Integer Overflow). Feedly's CWE estimate also suggests a potential out-of-bounds write (CWE-787) as a secondary consequence of the overflow (GitHub Advisory, Rockwell Advisory).
Successful exploitation causes the RSLinx Classic service to crash, rendering it unavailable until manually restarted. RSLinx Classic is widely used in industrial environments as a communication server bridging Rockwell Automation PLCs and SCADA/HMI systems, so a service outage can disrupt industrial operations, monitoring, and control functions. There is no evidence of confidentiality or integrity impact — the vulnerability is limited to availability. In OT/ICS environments, repeated or timed attacks could cause sustained operational disruptions (GitHub Advisory, CISA ICS Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability is rated as automatable by NVD SSVC, meaning it can be exploited without human interaction at scale. The EPSS score is approximately 0.31% (24th percentile), indicating a relatively low near-term exploitation probability. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (CISA ICS Advisory).
.dmp) generated in the RSLinx Classic installation directory or Windows crash dump locations following unexpected termination.Rockwell Automation has released a patch for this vulnerability, available via the official security advisory SD1794. Users should upgrade RSLinx Classic to a version beyond V4.50 as directed by the advisory. As a network-level workaround, restrict CIP protocol traffic (TCP/UDP port 44818 and 2222) to only authorized systems using firewalls or industrial DMZ architectures. Additionally, monitor RSLinx Classic service availability and configure automated alerting for unexpected service crashes to enable rapid response (Rockwell Advisory, GitHub Advisory, CISA ICS Advisory).
The vulnerability was covered in The Hacker News' weekly recap for September 2026, which highlighted it among notable ICS vulnerabilities (The Hacker News). CISA published an ICS advisory (ICSA-26-244-01) on the same day as disclosure, underscoring the relevance of the vulnerability to critical infrastructure operators (CISA ICS Advisory). Security aggregators including Tenable (Nessus plugin 342353) and AusCERT also published coverage shortly after disclosure (Tenable).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."