Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-9621: RSLinx Classic can crash from specially crafted network packet
CVE-2026-9621 · published 25 days ago
Summary
RSLinx Classic’s communication service may stop working if it receives a malformed CIP (Common Industrial Protocol) data packet. This can cause a denial‑of‑service condition, requiring a manual restart of the service. Install the latest Rockwell Automation update or restart the service promptly if it becomes unresponsive.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| rockwell automation | rslinx classic® | V4.50 and prior |
Original advisory text
RSLinx Classic® - Multiple Vulnerabilities
A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover
Severity
9.2
Critical
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-190Integer Overflow
Timeline
Published1 Sep 2026
Updated26 Sep 2026
First seen1 Sep 2026
Track software like this
Free during beta