Rockwellautomation
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Rockwellautomation product.
RSS Feeds for Rockwellautomation security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Rockwellautomation products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Rockwellautomation Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 39 vulnerabilities in Rockwellautomation with an average score of 7.8 out of ten. Last year, in 2025 Rockwellautomation had 42 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Rockwellautomation in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.13.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 39 | 7.80 |
| 2025 | 42 | 7.67 |
| 2024 | 45 | 8.11 |
| 2023 | 30 | 8.08 |
| 2022 | 31 | 8.30 |
| 2021 | 3 | 8.43 |
| 2020 | 25 | 7.74 |
| 2019 | 8 | 8.14 |
| 2018 | 6 | 5.50 |
It may take a day or so for new Rockwellautomation vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Rockwellautomation Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-12659 | Jul 14, 2026 |
DoS via erroneous CIP packet handling in Rockwell adapterA denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O. |
|
| CVE-2026-9128 | Jul 14, 2026 |
Studio 5000 Logix Designer: Unquoted Search Path Enables Arbitrary Code ExecA code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application. |
|
| CVE-2026-9636 | Jul 14, 2026 |
CIP Security Revocation Bypass in Rockwell Logix ControllersA security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections. |
|
| CVE-2026-9127 | Jul 14, 2026 |
Remote Code Execution via Incorrect Authorization in Studio 5000 Logix Designer Config FileA remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality. |
|
| CVE-2026-9108 | Jul 14, 2026 |
Path Traversal in Rockwell Studio 5000 Logix Designer ACD FilesA path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution. |
|
| CVE-2026-11917 | Jul 14, 2026 |
Path traversal in Rockwell ThinManager API allows file writeA path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. |
|
| CVE-2026-9292 | Jul 14, 2026 |
Stored XSS in FactoryTalk DataMosaix Private Cloud WorkflowsA Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website. |
|
| CVE-2025-11698 | Jul 14, 2026 |
Rockwell 5380/5480/5580 Controllers DoS via Boot Firmware <1.072A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF). |
|
| CVE-2025-12012 | Jul 14, 2026 |
Rockwell 5380/5480/5580 Controller DoS via Malformed File DataA denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF). |
|
| CVE-2025-12011 | Jul 14, 2026 |
DoS via Invalid Project Load in Rockwell 5370/5570 ControllersA denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF). |
|
| CVE-2026-10714 | Jul 14, 2026 |
FTSP Okta WebAuth JWT 'none' Alg BypassA security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP. |
|
| CVE-2026-9653 | Jul 14, 2026 |
CIP Implicit Conn DoS in Rockwell 1756-EN Comm ModuleA denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after. |
|
| CVE-2026-10573 | Jul 14, 2026 |
RWL 1734 POINT I/O DoS via Crafted CIP MsgsA denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. |
|
| CVE-2026-9140 | Jul 14, 2026 |
DENY-OF-SERVICE in Rockwell 1719-AENTR via UDP UNICAST StormA denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. |
|
| CVE-2026-8314 | Jul 14, 2026 |
Arena Simulation siman.exe OOB Write Enables Code ExecutionA security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. |
|
| CVE-2026-8313 | Jul 14, 2026 |
Arena Simulation linker.exe OOB Write Enables Code ExecutionA security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. |
|
| CVE-2026-8312 | Jul 14, 2026 |
Arena Simulation memory corruption in expmt.exe (preV17.00.00)A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. |
|
| CVE-2026-8085 | Jul 14, 2026 |
Arena Simulation OOB Write in model.exe (Siman)A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. |
|
| CVE-2026-0647 | Jun 16, 2026 |
Unauthenticated web server password reset in Rockwell 1794AENTRAn improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of the devices embedded web servers availability. |
|
| CVE-2026-0646 | Jun 16, 2026 |
Denial-of-Service in 1794-AENTR Adapter via CIP Memory HandlingA denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing connection to its associated I/O modules, requiring a manual reset to recover. |
|
| CVE-2025-14272 | Jun 16, 2026 |
Pavilion API Improper Authorization Allowing Unauth Privileged OpsA security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including user/role management and other administrative actions. |
|
| CVE-2025-13036 | Jun 16, 2026 |
FactoryTalk Historian Site Auth Bypass via Endless LoginAn authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token. |
|
| CVE-2026-9307 | Jun 16, 2026 |
CompactLogix Web Server CIP ID Disclosure DoSA sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service. |
|
| CVE-2025-11694 | Jun 16, 2026 |
CIP Sequence # & IP Validation Bug in 1769 CompactLogix Enables DoSA security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection IDs visible on the web interface to perform denial-of-service attacks, resulting in a minor fault. |
|
| CVE-2026-11317 | Jun 16, 2026 |
Denial of Service via crafted CIP message in Rockwell PLCA denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover. |
|
| CVE-2019-25276 | Feb 04, 2026 |
Studio 5000 Logix 30.01 Unquoted FTA Path ElevationStudio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject malicious code that would execute with LocalSystem permissions. |
|
| CVE-2025-9283 | Jan 20, 2026 |
CVE-2025-9283: ArmorStart LT Eth/IP DDoS via Achilles Step Limits StormsA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. |
|
| CVE-2025-9282 | Jan 20, 2026 |
DoS via Reboot in ArmorStart® LT During Achilles TestsA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. |
|
| CVE-2025-9281 | Jan 20, 2026 |
CVE-2025-9281: ArmorStart LT Device DOS via Achilles Storm TestA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots |
|
| CVE-2025-9280 | Jan 20, 2026 |
ArmorStart LT Device DoS from Defensics FuzzingA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot. |
|
| CVE-2025-14027 | Jan 20, 2026 |
DoS via Malformed Class 3 Messages in Rockwell Automation ControlLogixMultiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart. |
|
| CVE-2025-9279 | Jan 20, 2026 |
ArmorStart LT DoS via Achilles EtherNet/IP Step Limit Storm TestsA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. |
|
| CVE-2025-9278 | Jan 20, 2026 |
ICMP DoS in ArmorStart® LT triggered by Burp Suite active scanA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible. |
|
| CVE-2025-9466 | Jan 20, 2026 |
DDoS from Achilles ETL Tests on Rockwell ArmorStart LTA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. |
|
| CVE-2025-11743 | Jan 20, 2026 |
CVE-2025-11743: DoS via Malformed CIP Forward Open in Rockwell PLCA denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverable fault a restart is required to recover. |
|
| CVE-2025-9465 | Jan 20, 2026 |
ArmorStart LT DoS via Achilles Grammar Tests RebootA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. |
|
| CVE-2025-9464 | Jan 20, 2026 |
Denial-of-Service in ArmorStart LT via CIP FuzzingA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive. |
|
| CVE-2025-14377 | Jan 20, 2026 |
Verve Asset Manager: Legacy Ansible Playbook Plaintext Secrets before v1.36A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024. |
|
| CVE-2025-14376 | Jan 20, 2026 |
Plaintext Secrets in Verve Asset Manager ADI Server (1.36)A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the 1.36 release in 2024. |
|
| CVE-2025-13824 | Dec 15, 2025 |
PLC Hard Fault via Malformed CIP Packets (CPE 0xF019)A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code0xF019. To recover,clear the fault. |
|
| CVE-2025-13823 | Dec 15, 2025 |
IPv6 Stack Fault in Micro850/870 ControllersA security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple malformed packets during fuzzing. The controllers will go into recoverable fault with fault code 0xFE60. To recover the controller, clear the fault. |
|
| CVE-2025-9368 | Dec 09, 2025 |
DoS in GuardLink EtherNet/IP Interface on 432ES-IG3 Series AA security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device. |
|
| CVE-2025-12807 | Dec 09, 2025 |
DataMosaix Private Cloud API lowprivilege DB op flawA security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive database operations through exposed API endpoints. |
|
| CVE-2025-11918 | Nov 14, 2025 |
Arena DOE File Parsing Stack Buffer Overflow (CVE-2025-11918)Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file. |
|
| CVE-2025-11697 | Nov 11, 2025 |
Local Code Execution in Studio 5000 Simulation Interface API via Path TraversalA local code execution security issue exists within Studio 5000® Simulation Interface via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot. |
|
| CVE-2025-11696 | Nov 11, 2025 |
Studio 5000 Simulation Interface API SSRF Enables NTLM Hash CaptureA local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes. |
|
| CVE-2025-11862 | Nov 11, 2025 |
Verve Asset Manager API User Privilege Escalation (CVE-2025-11862)A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API. |
|
| CVE-2025-11085 | Nov 11, 2025 |
DataMosaix Private Cloud Persistent XSS Enabling JavaScript ExecutionA security issue exists within DataMosaix Private Cloud allowing for Persistent XSS. This vulnerability can result in the execution of malicious JavaScript, allowing for account takeover, credential theft, or redirection to a malicious website. |
|
| CVE-2025-11084 | Nov 11, 2025 |
DataMosaix Private Cloud MFA Bypass Obtain Auth Token Without PassA security issue exists within DataMosaix Private Cloud, allowing attackers to bypass MFA during setup and obtain a valid login-token cookie without knowing the users password. This vulnerability occurs when MFA is enabled but not completed within a 7-day period. |
|
| CVE-2025-9178 | Oct 14, 2025 |
CIP DoS via Crafted Payloads in EtherNet/IP Adapter 1715A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP communication using crafted payloads. The security issue could result in no CIP communication with 1715 EtherNet/IP Adapter.A restart is required to recover. |