security1 distinct publisher
One malformed CIP message faults a Logix controller until someone power-cycles it
Rockwell reported CVE-2026-9637 to CISA itself. A length validation bug in CIP handling drops ControlLogix, CompactLogix and GuardLogix controllers into a major nonrecoverable fault, and clearing it needs a person at the cabinet.
Publishers:cisa.gov
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−14
- Incentives45
- Confidence