Rockwellautomation Rockwellautomation

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Rockwellautomation product.

RSS Feeds for Rockwellautomation security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Rockwellautomation products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Rockwellautomation Sorted by Most Security Vulnerabilities since 2018

Rockwellautomation Arena43 vulnerabilities

Rockwellautomation Thinmanager16 vulnerabilities

Rockwellautomation Pavilion85 vulnerabilities

By the Year

In 2026 there have been 58 vulnerabilities in Rockwellautomation with an average score of 7.9 out of ten. Last year, in 2025 Rockwellautomation had 42 security vulnerabilities published. That is, 16 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.23.




Year Vulnerabilities Average Score
2026 58 7.90
2025 42 7.67
2024 45 8.11
2023 30 8.08
2022 31 8.30
2021 3 8.43
2020 25 7.74
2019 8 8.14
2018 6 5.50

It may take a day or so for new Rockwellautomation vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Rockwellautomation Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-6071 Sep 03, 2026
RCE via DOE file parse in Rockwell Automation A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.
Arena
CVE-2024-7956 Sep 02, 2026
Access Escalation in Rockwell FactoryTalk Projects (CVE-2024-7956) A vulnerability exists in the affected products that allows a threat actor to gain access to users projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project.
Datamosaix Private Cloud
CVE-2024-7953 Sep 01, 2026
Rockwell Admin Escalation via Project Creation A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project.
Dataedgeplatform Datamosaix Private Cloud
CVE-2024-7952 Sep 01, 2026
Data Exposure via Hardcoded JSON Links in Rockwell Automation A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authentication. If exploited, a threat actor could view customer data.
Dataedgeplatform Datamosaix Private Cloud
CVE-2026-9634 Sep 01, 2026
DLL Hijack via RMConfigTool.exe in Rockwell's Redundancy Module Configuration Tool A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.
Redundancy Module Configuration Tool
CVE-2026-9633 Sep 01, 2026
Elevated DLL Hijack via RM3ConfigTool.exe (Rockwell Automation) A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.
Redundancy Module Configuration Tool
CVE-2026-12661 Sep 01, 2026
DoS via buffer-overflow on FactoryTalk Historian Machine Edition web interface A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Factorytalk Historian Machine Edition
CVE-2025-12768 Sep 01, 2026
FactoryTalk Historian Machine Edition RCE via LowAuth Remote Exploit A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.
Factorytalk Historian Machine Edition
CVE-2026-9625 Sep 01, 2026
DoS in RSLinx Classic from oversized CIP packet A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
Rslinx Classic
CVE-2026-9624 Sep 01, 2026
DoS via crafted CIP packet in RSLinx Classic A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a  restart of the service to recover.
Rslinx Classic
CVE-2026-9622 Sep 01, 2026
DoS in RSLinx Classic via crafted CIP packet to Forward Close A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
Rslinx Classic
CVE-2026-9621 Sep 01, 2026
RSLinx Classic DoS via Malformed CIP Packet A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover
Rslinx Classic
CVE-2026-12663 Sep 01, 2026
ControlFLASH: Installer Grants 'Everyone' Write AccessATE Risk A security issue exists within ControlFLASH, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
Controlflash
CVE-2026-9637 Sep 01, 2026
Logix CIP Length Validation DoS in Rockwell Automation Platforms A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover
Compactlogix 5380 Controllogix 5580
CVE-2026-16675 Sep 01, 2026
FactoryTalk Activation Manager Priv Escalation via SYSTEM console windows A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.
Factorytalk Activation Manager
CVE-2026-84235 Sep 01, 2026
CVE-2026-84235: DoS via Crafted CIP Packet in Rockwell Automation ControlLogix A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.
1756 Enbt Module
CVE-2026-19472 Sep 01, 2026
Denial-of-Service via crafted HTTP PUT in ArmorStart® LT Embedded Web Server A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability
Armorstart Lt
CVE-2026-19471 Sep 01, 2026
ArmorStart LT Stored XSS Vulnerability Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.
Armorstart Lt
CVE-2026-75112 Aug 19, 2026
OTTO Fleet Mgmt bcrypt WF weak: offline brute force risk A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.
Otto Fleet Manager
CVE-2026-12659 Jul 14, 2026
DoS via erroneous CIP packet handling in Rockwell adapter A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O.
CVE-2026-9128 Jul 14, 2026
Studio 5000 Logix Designer: Unquoted Search Path Enables Arbitrary Code Exec A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.
CVE-2026-9636 Jul 14, 2026
CIP Security Revocation Bypass in Rockwell Logix Controllers A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.
CVE-2026-9127 Jul 14, 2026
Remote Code Execution via Incorrect Authorization in Studio 5000 Logix Designer Config File A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.
CVE-2026-9108 Jul 14, 2026
Path Traversal in Rockwell Studio 5000 Logix Designer ACD Files A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.
CVE-2026-11917 Jul 14, 2026
Path traversal in Rockwell ThinManager API allows file write A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.
Thinmanager
CVE-2026-9292 Jul 14, 2026
Stored XSS in FactoryTalk DataMosaix Private Cloud Workflows A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website.
Factorytalk Datamosaix Private Cloud
CVE-2025-11698 Jul 14, 2026
Rockwell 5380/5480/5580 Controllers DoS via Boot Firmware <1.072 A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
CVE-2025-12012 Jul 14, 2026
Rockwell 5380/5480/5580 Controller DoS via Malformed File Data A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
CVE-2025-12011 Jul 14, 2026
DoS via Invalid Project Load in Rockwell 5370/5570 Controllers A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).
Compactlogix 5370 Compact Guardlogix 5370 Controllogix 5570 Guardlogix 5570
CVE-2026-10714 Jul 14, 2026
FTSP Okta WebAuth JWT 'none' Alg Bypass A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP.
Factorytalk Services Platform
CVE-2026-9653 Jul 14, 2026
CIP Implicit Conn DoS in Rockwell 1756-EN Comm Module A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.
CVE-2026-10573 Jul 14, 2026
RWL 1734 POINT I/O DoS via Crafted CIP Msgs A denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover.
CVE-2026-9140 Jul 14, 2026
DENY-OF-SERVICE in Rockwell 1719-AENTR via UDP UNICAST Storm A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.
CVE-2026-8314 Jul 14, 2026
Arena Simulation siman.exe OOB Write Enables Code Execution A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Arena Simulation
CVE-2026-8313 Jul 14, 2026
Arena Simulation linker.exe OOB Write Enables Code Execution A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Arena Simulation
CVE-2026-8312 Jul 14, 2026
Arena Simulation memory corruption in expmt.exe (preV17.00.00) A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Arena Simulation
CVE-2026-8085 Jul 14, 2026
Arena Simulation OOB Write in model.exe (Siman) A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Arena Simulation
CVE-2026-0647 Jun 16, 2026
Unauthenticated web server password reset in Rockwell 1794AENTR An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of the devices embedded web servers availability.
CVE-2026-0646 Jun 16, 2026
Denial-of-Service in 1794-AENTR Adapter via CIP Memory Handling A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing connection to its associated I/O modules, requiring a manual reset to recover.
CVE-2025-14272 Jun 16, 2026
Pavilion API Improper Authorization Allowing Unauth Privileged Ops A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including user/role management and other administrative actions.
CVE-2025-13036 Jun 16, 2026
FactoryTalk Historian Site Auth Bypass via Endless Login An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
CVE-2026-9307 Jun 16, 2026
CompactLogix Web Server CIP ID Disclosure DoS A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.
CVE-2025-11694 Jun 16, 2026
CIP Sequence # & IP Validation Bug in 1769 CompactLogix Enables DoS A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection IDs visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.
CVE-2026-11317 Jun 16, 2026
Denial of Service via crafted CIP message in Rockwell PLC A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover.
CVE-2019-25276 Feb 04, 2026
Studio 5000 Logix 30.01 Unquoted FTA Path Elevation Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject malicious code that would execute with LocalSystem permissions.
CVE-2025-9283 Jan 20, 2026
CVE-2025-9283: ArmorStart LT Eth/IP DDoS via Achilles Step Limits Storms A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
CVE-2025-9282 Jan 20, 2026
DoS via Reboot in ArmorStart® LT During Achilles Tests A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
CVE-2025-9281 Jan 20, 2026
CVE-2025-9281: ArmorStart LT Device DOS via Achilles Storm Test A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots
CVE-2025-9280 Jan 20, 2026
ArmorStart LT Device DoS from Defensics Fuzzing A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.
CVE-2025-14027 Jan 20, 2026
DoS via Malformed Class 3 Messages in Rockwell Automation ControlLogix Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.