Security1 distinct publisher2 min readPublished
CVE-2021-42260 still drives a major nonrecoverable fault on ControlLogix, CompactLogix and GuardLogix hardware below four firmware branches. A faulted safety controller needs a program download before it runs again.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CWE-835 is the whole mechanism. A loop with an unreachable exit condition, per the advisory's own classification, means the controller does not drop a connection and carry on; it spins until the firmware declares a major nonrecoverable fault. Rockwell says corrupt crafted data is enough to trigger it.
The recovery line is where the cost sits, and it is not symmetric. A non-safety controller needs a stage 2 reset. A safety controller needs a program download. Both are deliberate acts by someone holding the project file, performed per controller, and neither is something a patch server does on your behalf. One malformed input buys the attacker a maintenance callout and, on the GuardLogix and Compact GuardLogix lines, a redownload of the safety program.
The version table is five product families against four firmware branches, which is twenty affected build entries: ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, Compact GuardLogix 5380 and CompactLogix 5480, each below 34.015, 35.014, 36.013 and 37.011. The lowest fixed build Rockwell lists is 34.015. Anything sitting on a branch older than 34 has no in-branch fix in this advisory and is looking at a major-branch move, with the validation and outage window that implies, rather than a point upgrade.
Then the date. The identifier is CVE-2021-42260 and the advisory is numbered in the 2026 ICSA series as ICSA-26-244-05, which puts roughly five years between the CVE reservation and this listing. The fix has existed for years across four branches. This is a firmware inventory problem: the number that matters to an asset owner is which of those four branches each rack is running, not the CVE age.
Rockwell reported the vulnerability to CISA itself. The advisory's Metrics heading carries no published CVSS score, and makes no claim of known exploitation or public exploit code. That combination puts this in the scheduling pile rather than the emergency pile, weighted by one question: whether the controller answers unsolicited traffic from anything beyond the control network. CISA's guidance is the standard set, keep control system devices off the internet, put them behind firewalls, isolate them from business networks, and use VPNs only where remote access is genuinely required.
For plants that cannot take the firmware, the only offered mitigation is Rockwell's security best practices, which governs who can reach the controller with corrupt data but leaves the loop itself in place. The products are deployed worldwide in critical manufacturing, so the population that has to make that trade is large and mostly running on outage calendars set months in advance.
Ranked by verification strength, evidence, and original report placement.
CISA advisory ICSA-26-244-05 lists CVE-2021-42260 as affecting Rockwell Automation ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, Compact GuardLogix 5380 and CompactLogix 5480 at versions below 34.015, 35.014, 36.013 and 37.011.
A potential denial of service vulnerability in the affected products can be triggered via corrupt crafted data and could result in a major nonrecoverable fault (MNRF).
A program download is required to recover safety controllers.
For non-safety controllers, a stage 2 reset is required to recover.
The relevant weakness is CWE-835, Loop with Unreachable Exit Condition ('Infinite Loop').
Rockwell Automation recommends users update to firmware version 34.015 and later, 35.014 and later, 36.013 and later, or 37.011 and later.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
A weak bcrypt setting turns every unencrypted OTTO Fleet Manager backup into a credential file1 distinct publisher
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
security
One malformed CIP message faults a Logix controller until someone power-cycles it1 distinct publisher
security
A low-privilege login reaches code execution on Rockwell's FactoryTalk Historian ME1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary, precise, and entirely unchecked
The version thresholds, the fault behaviour and the two recovery paths come straight from CISA's advisory, which is about as close to the record as ICS disclosure gets — and which credits Rockwell Automation as its own source. Precision is high and independence is zero: no researcher write-up, no proof-of-concept, and a Metrics heading with nothing under it, so the one number that would let an engineer triage this is missing.
No patch or exposure data exists here
Fixed firmware being published is not the same as fixed firmware being installed, and this reporting tracks only the former. Nobody counts the controllers still below 34.015, and CISA's 'worldwide, Critical Manufacturing' line is a classification field rather than an install-base figure. Even the exploitation statement is an absence of reports, not a measurement.
Undersold by its own paperwork
Nobody is inflating this one. A crafted-data fault that halts a safety controller until an engineer performs a program download is a production stoppage with a truck roll attached, and it is reported in the flat register of routine maintenance, severity score omitted. The understatement is structural rather than deliberate: the format has no room for what a stage 2 reset costs a running line.
Found, fixed and framed by the same vendor
Rockwell discovered the problem, wrote the patch and filed the report; CISA is the distribution channel, not an auditor. That arrangement is fast and it is also self-shaping — the fixed builds are prominent, while the questions a vendor has least reason to answer stay unanswered: why a 2021 identifier surfaces in a 2026 advisory, and what customers on pre-34 firmware are supposed to do.
Solid on facts, blind on severity and reach
We would stake a lot on the version numbers and the recovery steps; they are the vendor's own and there is no competing account to reconcile. What we cannot judge from this material is how much it matters — no score, no exploitation signal, no read on how much of the installed fleet sits below the corrected branches. Confidence in the what, not the how much.