CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Rockwell Automation Logix Platform

criticalCVE-2026-9637
View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) Compact GuardLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Logix Platform Improper Restriction of Operations within the Bounds of a Memory Buffer Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9637 A denial-of-service vulnerability exists in the affected Logix platforms due to improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover. View CVE Details Affected Products Rockwell Automation Logix Platform Vendor: Rockwell Automation Product Version: Rockwell Automation ControlLogix 5580 <=V33, Rockwell Automation ControlLogix 5580 V34.011-V34.014, Rockwell Automation ControlLogix 5580 V35.011-V35.013, Rockwell Automation ControlLogix 5580 V36.011-V36.012, Rockwell Automation CompactLogix 5380 <=V33, Rockwell Automation CompactLogix 5380 V34.011-V34.014, Rockwell Automation CompactLogix 5380 V35.011-V35.013, Rockwell Automation CompactLogix 5380 V36.011-V36.012, Rockwell Automation GuardLogix 5580 <=V33, Rockwell Automation GuardLogix 5580 V34.011-V34.014, Rockwell Automation GuardLogix 5580 V35.011-V35.013, Rockwell Automation GuardLogix 5580 V36.011-V36.012, Rockwell Automation

CSIRTS triage

vendor: Rockwell Automationproduct: Logix PlatformMemory corruptionaffected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012; CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012; GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-
What
Improper restriction of operations within memory buffer bounds allows out-of-bounds memory access.
Who is affected
Critical manufacturing environments worldwide running affected ControlLogix, CompactLogix, GuardLogix, and Compact GuardLogix 5380/5580 controllers.
Urgency
Critical severity with CVSS 7.5 and no active exploitation reported; immediate patching required for industrial control systems.
Action
Update to patched versions of Logix Platform controllers; contact Rockwell Automation for available fixed versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Logix Platform

Get an email when a new Logix Platform advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-09-01
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-9637coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Rockwell Automation Logix

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories