Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected: 1756-EN3 <=V12.001 (CVE-2026-9653) 1756-EN2 <=V12.001 (CVE-2026-9653) 1756-ENBT V6.006 (CVE-2026-9653) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT Improper Validation of Integrity Check Value Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9653 A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after. View CVE Details Affected Products Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT Vendor: Rockwell Automation Product Version: Rockwell Automation 1756-EN3: <=V12.001, Rockwell Automation 1756-EN2: <=V12.001, Rockwell Automation 1756-ENBT: V6.006 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users take the following actions: 1756-EN3: Update to V12.002 Vendor fix 1756-EN2: Update to V12.002 Vendor fix 1756-ENBT: Product is discontinued, fix is unavailable Relevant CWE: CWE-354 Improper Validation of Integrity Check Value Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Tyler Lentz of Idaho National Laboratory reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification)
CSIRTS triage
- What
- A denial-of-service vulnerability exists due to improper validation of packets.
- Who is affected
- Users of the affected Rockwell Automation communication modules.
- Urgency
- Remediation is critical due to the potential for network service disruption.
- Action
- Users should update to versions later than V12.001 or V6.006.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch 1756-EN2, 1756-EN3, and 1756-ENBT
Get an email when a new 1756-EN2, 1756-EN3, and 1756-ENBT advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-02
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-96530.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9653 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Rockwell Automation
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Modulecisa · 2026-07-30
- criticalRockwell Automation ThinManagercisa · 2026-07-23
- criticalRockwell Automation Studio 5000 Logix Designercisa · 2026-07-21
- criticalRockwell Automation 1734 POINT I/Ocisa · 2026-07-21
- criticalRockwell Automation FactoryTalk Services Platformcisa · 2026-07-21
- criticalRockwell Automation 1718-AENTR/1719-AENTRcisa · 2026-07-21
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30