Rockwell Automation Flex 5000 Adapter
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation Flex 5000 Adapter are affected: Flex 5000 Adapter 6.011 (CVE-2026-12659) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Flex 5000 Adapter Double Free Background Critical Infrastructure Sectors: Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-12659 A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O. View CVE Details Affected Products Rockwell Automation Flex 5000 Adapter Vendor: Rockwell Automation Product Version: Rockwell Automation Flex 5000 Adapter: 6.011 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users to upgrade to the following: Flex 5000 Adapter version 6.012. Mitigation Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see Rockwell Automation Security Advisory SD1789 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.html). https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.html Relevant CWE: CWE-415 Double Free Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4
CSIRTS triage
- What
- A denial-of-service security issue exists in the affected products.
- Who is affected
- Deployments of Flex 5000 Adapter version 6.011.
- Urgency
- Remediation is urgent due to the critical nature of the vulnerability and the potential for service disruption.
- Action
- A power cycle is required to recover the module and associated I/O.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Flex 5000 Adapter
Get an email when a new Flex 5000 Adapter advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-08
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-126590.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-12659 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30