CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-9653

criticalcovered by 2 sourcesfirst seen 2026-07-14
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected: 1756-EN3 <=V12.001 (CVE-2026-9653) 1756-EN2 <=V12.001 (CVE-2026-9653) 1756-ENBT V6.006 (CVE-2026-9653) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT Improper Validation of Integrity Check Value Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9653 A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after. View CVE Details Affected Products Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT Vendor: Rockwell Automation Product Version: Rockwell Automation 1756-EN3: <=V12.001, Rockwell Automation 1756-EN2: <=V12.001, Rockwell Automation 1756-ENBT: V6.006 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users take the following actions: 1756-EN3: Update to V12.002 Vendor fix 1756-EN2: Update to V12.002 Vendor fix 1756-ENBT: Product is discontinued, fix is unavailable Relevant CWE: CWE-354 Improper Validation of Integrity Check Value Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Tyler Lentz of Idaho National Laboratory reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification)

CSIRTS triage

What
A denial-of-service vulnerability exists due to improper validation of packets.
Who is affected
Users of the affected Rockwell Automation communication modules.
Urgency
Remediation is critical due to the potential for network service disruption.
Action
Users should update to versions later than V12.001 or V6.006.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-9653

Get an email if CVE-2026-9653 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-9653

CVE.org record

Embed the live status

CVE-2026-9653 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-9653 status](https://www.csirts.com/badge/CVE-2026-9653)](https://www.csirts.com/cve/CVE-2026-9653)