Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-9621: RSLinx Classic can crash from specially crafted network packet

CVE-2026-9621 · published 25 days ago
Summary

RSLinx Classic’s communication service may stop working if it receives a malformed CIP (Common Industrial Protocol) data packet. This can cause a denial‑of‑service condition, requiring a manual restart of the service. Install the latest Rockwell Automation update or restart the service promptly if it becomes unresponsive.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
rockwell automation rslinx classic® V4.50 and prior
Original advisory text
RSLinx Classic® - Multiple Vulnerabilities
A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover
Severity
9.2 Critical
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-190Integer Overflow
Timeline
Published1 Sep 2026
Updated26 Sep 2026
First seen1 Sep 2026
Sources
CVE-2026-9621 · NVD
CVE-2026-9621 · MITRE
Track software like this
Free during beta