
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-9622 is a denial-of-service vulnerability in Rockwell Automation RSLinx® Classic that allows an unauthenticated remote attacker to crash the service by sending a specially crafted CIP (Common Industrial Protocol) packet targeting the Forward Close service. The affected versions are RSLinx® Classic V4.50 and prior. The vulnerability was published on September 1, 2026, and a patch is available. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Rockwell Advisory).
The root cause is classified as CWE-191 (Integer Underflow / Wrap or Wraparound), where a subtraction operation produces a result less than the minimum allowable integer value, leading to unexpected behavior in the RSLinx® Classic service. An unauthenticated attacker on the network can send a malformed CIP packet specifically targeting the Forward Close service handler, triggering the integer underflow condition and causing the service process to crash. No authentication, user interaction, or special attack conditions are required, making exploitation straightforward for any network-accessible attacker. No public proof-of-concept code has been identified at this time (GitHub Advisory, Rockwell Advisory).
Successful exploitation results in a crash of the RSLinx® Classic service, which must be manually restarted to restore functionality. RSLinx® Classic is widely used as a communication driver for Rockwell Automation industrial control systems (ICS), so a service crash can disrupt communications between engineering workstations and PLCs/controllers in operational technology (OT) environments. There is no evidence of confidentiality or integrity impact; the vulnerability is limited to availability. In industrial settings, loss of this communication layer can halt monitoring, configuration, and control operations, potentially impacting production continuity (GitHub Advisory, CISA ICS Advisory).
No public proof-of-concept exploit code has been reported, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.312% (24th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is rated as automatable by SSVC assessment, meaning an attacker could script repeated denial-of-service attacks without manual intervention. No threat actor attribution has been identified (GitHub Advisory, CISA ICS Advisory).
RSLinx.exe) after it was previously running; automated or manual service restart activity recorded in system logs.Rockwell Automation has released a security patch for RSLinx® Classic addressing this vulnerability; users should apply the update available through Rockwell Automation's official support channels (advisory SD1794). Until patching is possible, implement network segmentation to restrict access to RSLinx® Classic hosts from untrusted network sources, and use industrial firewalls or DMZ architectures to limit CIP traffic to authorized devices only. Monitor for anomalous CIP packet traffic targeting the Forward Close service as an additional detection measure (Rockwell Advisory, CISA ICS Advisory).
CISA published an ICS advisory (ICSA-26-244-01) covering this vulnerability, highlighting its relevance to industrial control system operators (CISA ICS Advisory). The vulnerability was also noted in The Hacker News weekly recap and covered by ICS-focused security outlets such as meterpreter.org, reflecting moderate community awareness given its impact on widely deployed industrial software (The Hacker News). AusCERT issued a bulletin (ESB-2026.10353) to notify its constituency of the advisory.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."