Rockwell Automation Logix Platform
View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) Compact GuardLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Logix Platform Improper Restriction of Operations within the Bounds of a Memory Buffer Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9637 A denial-of-service vulnerability exists in the affected Logix platforms due to improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover. View CVE Details Affected Products Rockwell Automation Logix Platform Vendor: Rockwell Automation Product Version: Rockwell Automation ControlLogix 5580 <=V33, Rockwell Automation ControlLogix 5580 V34.011-V34.014, Rockwell Automation ControlLogix 5580 V35.011-V35.013, Rockwell Automation ControlLogix 5580 V36.011-V36.012, Rockwell Automation CompactLogix 5380 <=V33, Rockwell Automation CompactLogix 5380 V34.011-V34.014, Rockwell Automation CompactLogix 5380 V35.011-V35.013, Rockwell Automation CompactLogix 5380 V36.011-V36.012, Rockwell Automation GuardLogix 5580 <=V33, Rockwell Automation GuardLogix 5580 V34.011-V34.014, Rockwell Automation GuardLogix 5580 V35.011-V35.013, Rockwell Automation GuardLogix 5580 V36.011-V36.012, Rockwell Automation
CSIRTS triage
- What
- Improper restriction of operations within memory buffer bounds allows out-of-bounds memory access.
- Who is affected
- Critical manufacturing environments worldwide running affected ControlLogix, CompactLogix, GuardLogix, and Compact GuardLogix 5380/5580 controllers.
- Urgency
- Critical severity with CVSS 7.5 and no active exploitation reported; immediate patching required for industrial control systems.
- Action
- Update to patched versions of Logix Platform controllers; contact Rockwell Automation for available fixed versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Logix Platform
Get an email when a new Logix Platform advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-96370.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9637 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Rockwell Automation Logix
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalRockwell Automation Studio 5000 Logix Designercisa · 2026-07-21
- medium[NEW] [medium] Rockwell Automation Studio 5000 Logix Designer: Multiple vulnerabilities allow code executioncert-bund · 2026-07-15
More from CISA Cybersecurity Advisories
- criticalCommunicating Under Pressure: Best Practices for Service Providers2026-09-02
- highCISA Adds Seven Known Exploited Vulnerabilities to Catalog2026-09-02
- criticalRockwell Automation Redundancy Module Configuration Tool2026-09-01
- criticalRockwell Automation FactoryTalk Activation Manager2026-09-01
- criticalRockwell Automation Historian ME2026-09-01