Rockwell Automation Patches Over a Dozen Vulnerabilities Across
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.
By Dillip Chowdary • Sep 02, 2026 • Source: SecurityWeek
What happened
Rockwell Automation has released a comprehensive suite of security advisories addressing more than a dozen vulnerabilities discovered across its major industrial software and hardware product lines. The security updates patch security flaws found in widely deployed systems, including RSLinx Classic, ArmorStart, ControlFLASH, and FactoryTalk. Industrial organizations rely on these systems to configure, monitor, and control physical machinery in critical infrastructure environments, making the resolution of these vulnerabilities a high priority
Rockwell Automation on Tuesday informed customers that patches or workarounds are available for more than a dozen vulnerabilities discovered across its industrial automation products. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software.
How it works

Exploitation can cause the RSLinx Classic service to crash, requiring a restart for recovery. Rockwell’s advisory for CVE-2026-9637, a high-severity DoS flaw in ControlLogix and CompactLogix controllers, flags the vulnerability as exploited.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Why it matters
However, it’s likely an error, as it’s only listed as such in the document’s header; elsewhere it’s listed as not exploited. See the full write-up from SecurityWeek via the source link for quotes and complete context.
Who is affected
Read the original coverage at SecurityWeek via the source link above for the complete details and primary quotes.
What to watch next
Cross-check release notes and official docs before changing production systems based on early reporting.
Developer Action Items
- ☐ Inventory whether Rockwell Automation Patches Dozen runs in prod, CI, staging, or on laptops before you debate severity.
- ☐ Pull the vendor advisory for CVE-2026-9637 and patch from that page — not from a social recap.
- ☐ If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
- ☐ Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Elastic Stack 8.19.21 released
Read →
OpenAI Details GPT-Live’s Architecture for Continuous Stateful Voice Interaction
Read →
OpenAI accused of ‘aiding and abetting’ Tumbler Ridge mass shooting in dozens of new…
Read →
Claude's new system prompt doesn't want to reproduce song lyrics
Read →
Today's Tech Pulse briefing
Full briefing →
Advertisement