ROCKWELL Automation has released patches and workarounds for numerous vulnerabilities identified in its industrial automation products. One critical advisory highlights four denial-of-service (DoS) vulnerabilities affecting RSLinx Classic communications software, which can lead to service crashes. A separate advisory for CVE-2026-9637 mentions a high-severity DoS flaw in ControlLogix and CompactLogix controllers but notes potential discrepancies in exploitation claims.
Additionally, vulnerabilities in FactoryTalk products have been addressed, including a high-severity remote code execution issue and multiple cross-site scripting vulnerabilities. Other affected utilities include ControlFLASH and the Redundancy Module Configuration Tool, indicating a range of security improvements implemented by Rockwell.