Rockwellautomation
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Rockwellautomation product.
RSS Feeds for Rockwellautomation security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Rockwellautomation products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Rockwellautomation Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 58 vulnerabilities in Rockwellautomation with an average score of 7.9 out of ten. Last year, in 2025 Rockwellautomation had 42 security vulnerabilities published. That is, 16 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.23.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 58 | 7.90 |
| 2025 | 42 | 7.67 |
| 2024 | 45 | 8.11 |
| 2023 | 30 | 8.08 |
| 2022 | 31 | 8.30 |
| 2021 | 3 | 8.43 |
| 2020 | 25 | 7.74 |
| 2019 | 8 | 8.14 |
| 2018 | 6 | 5.50 |
It may take a day or so for new Rockwellautomation vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Rockwellautomation Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-6071 | Sep 03, 2026 |
RCE via DOE file parse in Rockwell AutomationA remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file. |
|
| CVE-2024-7956 | Sep 02, 2026 |
Access Escalation in Rockwell FactoryTalk Projects (CVE-2024-7956)A vulnerability exists in the affected products that allows a threat actor to gain access to users projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project. |
|
| CVE-2024-7953 | Sep 01, 2026 |
Rockwell Admin Escalation via Project CreationA vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project. |
|
| CVE-2024-7952 | Sep 01, 2026 |
Data Exposure via Hardcoded JSON Links in Rockwell AutomationA data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authentication. If exploited, a threat actor could view customer data. |
|
| CVE-2026-9634 | Sep 01, 2026 |
DLL Hijack via RMConfigTool.exe in Rockwell's Redundancy Module Configuration ToolA security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges. |
|
| CVE-2026-9633 | Sep 01, 2026 |
Elevated DLL Hijack via RM3ConfigTool.exe (Rockwell Automation)A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges. |
|
| CVE-2026-12661 | Sep 01, 2026 |
DoS via buffer-overflow on FactoryTalk Historian Machine Edition web interfaceA denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive. |
|
| CVE-2025-12768 | Sep 01, 2026 |
FactoryTalk Historian Machine Edition RCE via LowAuth Remote ExploitA security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device. |
|
| CVE-2026-9625 | Sep 01, 2026 |
DoS in RSLinx Classic from oversized CIP packetA denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover. |
|
| CVE-2026-9624 | Sep 01, 2026 |
DoS via crafted CIP packet in RSLinx ClassicA denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover. |
|
| CVE-2026-9622 | Sep 01, 2026 |
DoS in RSLinx Classic via crafted CIP packet to Forward CloseA denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover. |
|
| CVE-2026-9621 | Sep 01, 2026 |
RSLinx Classic DoS via Malformed CIP PacketA denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover |
|
| CVE-2026-12663 | Sep 01, 2026 |
ControlFLASH: Installer Grants 'Everyone' Write AccessATE RiskA security issue exists within ControlFLASH, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. |
|
| CVE-2026-9637 | Sep 01, 2026 |
Logix CIP Length Validation DoS in Rockwell Automation PlatformsA denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover |
|
| CVE-2026-16675 | Sep 01, 2026 |
FactoryTalk Activation Manager Priv Escalation via SYSTEM console windowsA privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources. |
|
| CVE-2026-84235 | Sep 01, 2026 |
CVE-2026-84235: DoS via Crafted CIP Packet in Rockwell Automation ControlLogixA denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover. |
|
| CVE-2026-19472 | Sep 01, 2026 |
Denial-of-Service via crafted HTTP PUT in ArmorStart® LT Embedded Web ServerA denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability |
|
| CVE-2026-19471 | Sep 01, 2026 |
ArmorStart LT Stored XSS VulnerabilityMultiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page. |
|
| CVE-2026-75112 | Aug 19, 2026 |
OTTO Fleet Mgmt bcrypt WF weak: offline brute force riskA security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised. |
|
| CVE-2026-12659 | Jul 14, 2026 |
DoS via erroneous CIP packet handling in Rockwell adapterA denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O. |
|
| CVE-2026-9128 | Jul 14, 2026 |
Studio 5000 Logix Designer: Unquoted Search Path Enables Arbitrary Code ExecA code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application. |
|
| CVE-2026-9636 | Jul 14, 2026 |
CIP Security Revocation Bypass in Rockwell Logix ControllersA security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections. |
|
| CVE-2026-9127 | Jul 14, 2026 |
Remote Code Execution via Incorrect Authorization in Studio 5000 Logix Designer Config FileA remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality. |
|
| CVE-2026-9108 | Jul 14, 2026 |
Path Traversal in Rockwell Studio 5000 Logix Designer ACD FilesA path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution. |
|
| CVE-2026-11917 | Jul 14, 2026 |
Path traversal in Rockwell ThinManager API allows file writeA path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. |
|
| CVE-2026-9292 | Jul 14, 2026 |
Stored XSS in FactoryTalk DataMosaix Private Cloud WorkflowsA Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website. |
|
| CVE-2025-11698 | Jul 14, 2026 |
Rockwell 5380/5480/5580 Controllers DoS via Boot Firmware <1.072A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF). |
|
| CVE-2025-12012 | Jul 14, 2026 |
Rockwell 5380/5480/5580 Controller DoS via Malformed File DataA denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF). |
|
| CVE-2025-12011 | Jul 14, 2026 |
DoS via Invalid Project Load in Rockwell 5370/5570 ControllersA denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF). |
|
| CVE-2026-10714 | Jul 14, 2026 |
FTSP Okta WebAuth JWT 'none' Alg BypassA security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP. |
|
| CVE-2026-9653 | Jul 14, 2026 |
CIP Implicit Conn DoS in Rockwell 1756-EN Comm ModuleA denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after. |
|
| CVE-2026-10573 | Jul 14, 2026 |
RWL 1734 POINT I/O DoS via Crafted CIP MsgsA denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. |
|
| CVE-2026-9140 | Jul 14, 2026 |
DENY-OF-SERVICE in Rockwell 1719-AENTR via UDP UNICAST StormA denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. |
|
| CVE-2026-8314 | Jul 14, 2026 |
Arena Simulation siman.exe OOB Write Enables Code ExecutionA security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. |
|
| CVE-2026-8313 | Jul 14, 2026 |
Arena Simulation linker.exe OOB Write Enables Code ExecutionA security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. |
|
| CVE-2026-8312 | Jul 14, 2026 |
Arena Simulation memory corruption in expmt.exe (preV17.00.00)A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. |
|
| CVE-2026-8085 | Jul 14, 2026 |
Arena Simulation OOB Write in model.exe (Siman)A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. |
|
| CVE-2026-0647 | Jun 16, 2026 |
Unauthenticated web server password reset in Rockwell 1794AENTRAn improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of the devices embedded web servers availability. |
|
| CVE-2026-0646 | Jun 16, 2026 |
Denial-of-Service in 1794-AENTR Adapter via CIP Memory HandlingA denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing connection to its associated I/O modules, requiring a manual reset to recover. |
|
| CVE-2025-14272 | Jun 16, 2026 |
Pavilion API Improper Authorization Allowing Unauth Privileged OpsA security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including user/role management and other administrative actions. |
|
| CVE-2025-13036 | Jun 16, 2026 |
FactoryTalk Historian Site Auth Bypass via Endless LoginAn authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token. |
|
| CVE-2026-9307 | Jun 16, 2026 |
CompactLogix Web Server CIP ID Disclosure DoSA sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service. |
|
| CVE-2025-11694 | Jun 16, 2026 |
CIP Sequence # & IP Validation Bug in 1769 CompactLogix Enables DoSA security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection IDs visible on the web interface to perform denial-of-service attacks, resulting in a minor fault. |
|
| CVE-2026-11317 | Jun 16, 2026 |
Denial of Service via crafted CIP message in Rockwell PLCA denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover. |
|
| CVE-2019-25276 | Feb 04, 2026 |
Studio 5000 Logix 30.01 Unquoted FTA Path ElevationStudio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject malicious code that would execute with LocalSystem permissions. |
|
| CVE-2025-9283 | Jan 20, 2026 |
CVE-2025-9283: ArmorStart LT Eth/IP DDoS via Achilles Step Limits StormsA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. |
|
| CVE-2025-9282 | Jan 20, 2026 |
DoS via Reboot in ArmorStart® LT During Achilles TestsA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. |
|
| CVE-2025-9281 | Jan 20, 2026 |
CVE-2025-9281: ArmorStart LT Device DOS via Achilles Storm TestA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots |
|
| CVE-2025-9280 | Jan 20, 2026 |
ArmorStart LT Device DoS from Defensics FuzzingA security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot. |
|
| CVE-2025-14027 | Jan 20, 2026 |
DoS via Malformed Class 3 Messages in Rockwell Automation ControlLogixMultiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart. |