Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-9622
Rockwell Automation RSLinx Classic vulnerability analysis and mitigation

Overview

CVE-2026-9622 is a denial-of-service vulnerability in Rockwell Automation RSLinx® Classic that allows an unauthenticated remote attacker to crash the service by sending a specially crafted CIP (Common Industrial Protocol) packet targeting the Forward Close service. The affected versions are RSLinx® Classic V4.50 and prior. The vulnerability was published on September 1, 2026, and a patch is available. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Rockwell Advisory).

Technical details

The root cause is classified as CWE-191 (Integer Underflow / Wrap or Wraparound), where a subtraction operation produces a result less than the minimum allowable integer value, leading to unexpected behavior in the RSLinx® Classic service. An unauthenticated attacker on the network can send a malformed CIP packet specifically targeting the Forward Close service handler, triggering the integer underflow condition and causing the service process to crash. No authentication, user interaction, or special attack conditions are required, making exploitation straightforward for any network-accessible attacker. No public proof-of-concept code has been identified at this time (GitHub Advisory, Rockwell Advisory).

Impact

Successful exploitation results in a crash of the RSLinx® Classic service, which must be manually restarted to restore functionality. RSLinx® Classic is widely used as a communication driver for Rockwell Automation industrial control systems (ICS), so a service crash can disrupt communications between engineering workstations and PLCs/controllers in operational technology (OT) environments. There is no evidence of confidentiality or integrity impact; the vulnerability is limited to availability. In industrial settings, loss of this communication layer can halt monitoring, configuration, and control operations, potentially impacting production continuity (GitHub Advisory, CISA ICS Advisory).

Exploitability

No public proof-of-concept exploit code has been reported, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.312% (24th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is rated as automatable by SSVC assessment, meaning an attacker could script repeated denial-of-service attacks without manual intervention. No threat actor attribution has been identified (GitHub Advisory, CISA ICS Advisory).

Exploitation steps

  1. Reconnaissance: Identify hosts running RSLinx® Classic V4.50 or earlier on the network using industrial protocol scanners (e.g., tools supporting EtherNet/IP or CIP enumeration) or by scanning for TCP port 44818, the default EtherNet/IP port used by RSLinx® Classic.
  2. Craft malicious CIP packet: Construct a CIP packet targeting the Forward Close service with a malformed payload designed to trigger an integer underflow in the RSLinx® Classic service's packet parsing logic.
  3. Transmit packet: Send the crafted CIP packet to the target host over the network. No authentication credentials or prior session establishment are required.
  4. Achieve denial of service: The integer underflow condition causes the RSLinx® Classic service to crash. The service will remain unavailable until an administrator manually restarts it, disrupting ICS communications (GitHub Advisory, Rockwell Advisory).

Indicators of compromise

  • Network: Unexpected or malformed CIP packets (EtherNet/IP, TCP port 44818) targeting the Forward Close service from unknown or untrusted source IP addresses; repeated connection attempts to RSLinx® Classic from external network segments.
  • Logs: RSLinx® Classic service crash events or unexpected service termination entries in Windows Event Logs (Application/System logs); service restart events logged shortly after anomalous network activity.
  • Process: Absence of the RSLinx® Classic process (RSLinx.exe) after it was previously running; automated or manual service restart activity recorded in system logs.

Mitigation and workarounds

Rockwell Automation has released a security patch for RSLinx® Classic addressing this vulnerability; users should apply the update available through Rockwell Automation's official support channels (advisory SD1794). Until patching is possible, implement network segmentation to restrict access to RSLinx® Classic hosts from untrusted network sources, and use industrial firewalls or DMZ architectures to limit CIP traffic to authorized devices only. Monitor for anomalous CIP packet traffic targeting the Forward Close service as an additional detection measure (Rockwell Advisory, CISA ICS Advisory).

Community reactions

CISA published an ICS advisory (ICSA-26-244-01) covering this vulnerability, highlighting its relevance to industrial control system operators (CISA ICS Advisory). The vulnerability was also noted in The Hacker News weekly recap and covered by ICS-focused security outlets such as meterpreter.org, reflecting moderate community awareness given its impact on widely deployed industrial software (The Hacker News). AusCERT issued a bulletin (ESB-2026.10353) to notify its constituency of the advisory.

Additional resources


SourceThis report was generated using AI

Related Rockwell Automation RSLinx Classic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9621CRITICAL9.2
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9625HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9624HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9622HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2020-13573HIGH7.5
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesJan 07, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management