Vulnerability intelligence
CVE-2026-9653
A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.
CVSS Score
8.7
High
EPSS — Exploit Probability
0.2%
Riskier than 8% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jul 16, 2026 · latest Jul 16, 2026
Coverage timeline
-
Rockwell bug permits DoS attacks using CVE-2026-9653www.cisa.gov · Jul 16, 2026