Rockwellautomation Rockwellautomation

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Rockwellautomation product.

RSS Feeds for Rockwellautomation security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Rockwellautomation products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Rockwellautomation Sorted by Most Security Vulnerabilities since 2018

Rockwellautomation Arena42 vulnerabilities

Rockwellautomation Thinmanager16 vulnerabilities

Rockwellautomation Pavilion85 vulnerabilities

By the Year

In 2026 there have been 39 vulnerabilities in Rockwellautomation with an average score of 7.8 out of ten. Last year, in 2025 Rockwellautomation had 42 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Rockwellautomation in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.13.




Year Vulnerabilities Average Score
2026 39 7.80
2025 42 7.67
2024 45 8.11
2023 30 8.08
2022 31 8.30
2021 3 8.43
2020 25 7.74
2019 8 8.14
2018 6 5.50

It may take a day or so for new Rockwellautomation vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Rockwellautomation Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-12659 Jul 14, 2026
DoS via erroneous CIP packet handling in Rockwell adapter A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O.
CVE-2026-9128 Jul 14, 2026
Studio 5000 Logix Designer: Unquoted Search Path Enables Arbitrary Code Exec A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.
CVE-2026-9636 Jul 14, 2026
CIP Security Revocation Bypass in Rockwell Logix Controllers A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.
CVE-2026-9127 Jul 14, 2026
Remote Code Execution via Incorrect Authorization in Studio 5000 Logix Designer Config File A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.
CVE-2026-9108 Jul 14, 2026
Path Traversal in Rockwell Studio 5000 Logix Designer ACD Files A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.
CVE-2026-11917 Jul 14, 2026
Path traversal in Rockwell ThinManager API allows file write A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.
Thinmanager
CVE-2026-9292 Jul 14, 2026
Stored XSS in FactoryTalk DataMosaix Private Cloud Workflows A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website.
Factorytalk Datamosaix Private Cloud
CVE-2025-11698 Jul 14, 2026
Rockwell 5380/5480/5580 Controllers DoS via Boot Firmware <1.072 A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
CVE-2025-12012 Jul 14, 2026
Rockwell 5380/5480/5580 Controller DoS via Malformed File Data A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
CVE-2025-12011 Jul 14, 2026
DoS via Invalid Project Load in Rockwell 5370/5570 Controllers A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).
CVE-2026-10714 Jul 14, 2026
FTSP Okta WebAuth JWT 'none' Alg Bypass A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP.
Factorytalk Services Platform
CVE-2026-9653 Jul 14, 2026
CIP Implicit Conn DoS in Rockwell 1756-EN Comm Module A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.
CVE-2026-10573 Jul 14, 2026
RWL 1734 POINT I/O DoS via Crafted CIP Msgs A denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover.
CVE-2026-9140 Jul 14, 2026
DENY-OF-SERVICE in Rockwell 1719-AENTR via UDP UNICAST Storm A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.
CVE-2026-8314 Jul 14, 2026
Arena Simulation siman.exe OOB Write Enables Code Execution A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Arena Simulation
CVE-2026-8313 Jul 14, 2026
Arena Simulation linker.exe OOB Write Enables Code Execution A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Arena Simulation
CVE-2026-8312 Jul 14, 2026
Arena Simulation memory corruption in expmt.exe (preV17.00.00) A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Arena Simulation
CVE-2026-8085 Jul 14, 2026
Arena Simulation OOB Write in model.exe (Siman) A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Arena Simulation
CVE-2026-0647 Jun 16, 2026
Unauthenticated web server password reset in Rockwell 1794AENTR An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of the devices embedded web servers availability.
CVE-2026-0646 Jun 16, 2026
Denial-of-Service in 1794-AENTR Adapter via CIP Memory Handling A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing connection to its associated I/O modules, requiring a manual reset to recover.
CVE-2025-14272 Jun 16, 2026
Pavilion API Improper Authorization Allowing Unauth Privileged Ops A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including user/role management and other administrative actions.
CVE-2025-13036 Jun 16, 2026
FactoryTalk Historian Site Auth Bypass via Endless Login An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
CVE-2026-9307 Jun 16, 2026
CompactLogix Web Server CIP ID Disclosure DoS A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.
CVE-2025-11694 Jun 16, 2026
CIP Sequence # & IP Validation Bug in 1769 CompactLogix Enables DoS A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection IDs visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.
CVE-2026-11317 Jun 16, 2026
Denial of Service via crafted CIP message in Rockwell PLC A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover.
CVE-2019-25276 Feb 04, 2026
Studio 5000 Logix 30.01 Unquoted FTA Path Elevation Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject malicious code that would execute with LocalSystem permissions.
CVE-2025-9283 Jan 20, 2026
CVE-2025-9283: ArmorStart LT Eth/IP DDoS via Achilles Step Limits Storms A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
CVE-2025-9282 Jan 20, 2026
DoS via Reboot in ArmorStart® LT During Achilles Tests A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
CVE-2025-9281 Jan 20, 2026
CVE-2025-9281: ArmorStart LT Device DOS via Achilles Storm Test A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots
CVE-2025-9280 Jan 20, 2026
ArmorStart LT Device DoS from Defensics Fuzzing A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.
CVE-2025-14027 Jan 20, 2026
DoS via Malformed Class 3 Messages in Rockwell Automation ControlLogix Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.
CVE-2025-9279 Jan 20, 2026
ArmorStart LT DoS via Achilles EtherNet/IP Step Limit Storm Tests A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
CVE-2025-9278 Jan 20, 2026
ICMP DoS in ArmorStart® LT triggered by Burp Suite active scan A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible.
CVE-2025-9466 Jan 20, 2026
DDoS from Achilles ETL Tests on Rockwell ArmorStart LT A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
CVE-2025-11743 Jan 20, 2026
CVE-2025-11743: DoS via Malformed CIP Forward Open in Rockwell PLC A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverable fault a restart is required to recover.
CVE-2025-9465 Jan 20, 2026
ArmorStart LT DoS via Achilles Grammar Tests Reboot A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
CVE-2025-9464 Jan 20, 2026
Denial-of-Service in ArmorStart LT via CIP Fuzzing A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive.
CVE-2025-14377 Jan 20, 2026
Verve Asset Manager: Legacy Ansible Playbook Plaintext Secrets before v1.36 A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024.
CVE-2025-14376 Jan 20, 2026
Plaintext Secrets in Verve Asset Manager ADI Server (1.36) A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the 1.36 release in 2024.
CVE-2025-13824 Dec 15, 2025
PLC Hard Fault via Malformed CIP Packets (CPE 0xF019) A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code0xF019. To recover,clear the fault.
CVE-2025-13823 Dec 15, 2025
IPv6 Stack Fault in Micro850/870 Controllers A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple malformed packets during fuzzing. The controllers will go into recoverable fault with fault code 0xFE60. To recover the controller, clear the fault.
CVE-2025-9368 Dec 09, 2025
DoS in GuardLink EtherNet/IP Interface on 432ES-IG3 Series A A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device.
CVE-2025-12807 Dec 09, 2025
DataMosaix Private Cloud API lowprivilege DB op flaw A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive database operations through exposed API endpoints.
Factorytalk Datamosaix Private Cloud
CVE-2025-11918 Nov 14, 2025
Arena DOE File Parsing Stack Buffer Overflow (CVE-2025-11918) Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.
Arena Simulation
Arena
CVE-2025-11697 Nov 11, 2025
Local Code Execution in Studio 5000 Simulation Interface API via Path Traversal A local code execution security issue exists within Studio 5000® Simulation Interface via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.
Studio 5000 Simulation Interface
CVE-2025-11696 Nov 11, 2025
Studio 5000 Simulation Interface API SSRF Enables NTLM Hash Capture A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes.
Studio 5000 Simulation Interface
CVE-2025-11862 Nov 11, 2025
Verve Asset Manager API User Privilege Escalation (CVE-2025-11862) A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API.
Verve Asset Manager
CVE-2025-11085 Nov 11, 2025
DataMosaix Private Cloud Persistent XSS Enabling JavaScript Execution A security issue exists within DataMosaix Private Cloud allowing for Persistent XSS. This vulnerability can result in the execution of malicious JavaScript, allowing for account takeover, credential theft, or redirection to a malicious website.
Factorytalk Datamosaix Private Cloud
CVE-2025-11084 Nov 11, 2025
DataMosaix Private Cloud MFA Bypass Obtain Auth Token Without Pass A security issue exists within DataMosaix Private Cloud, allowing attackers to bypass MFA during setup and obtain a valid login-token cookie without knowing the users password. This vulnerability occurs when MFA is enabled but not completed within a 7-day period.
Factorytalk Datamosaix Private Cloud
CVE-2025-9178 Oct 14, 2025
CIP DoS via Crafted Payloads in EtherNet/IP Adapter 1715 A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP communication using crafted payloads. The security issue could result in no CIP communication with 1715 EtherNet/IP Adapter.A restart is required to recover.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.