Security1 distinct publisher2 min readPublished
Rockwell reported CVE-2026-9637 to CISA itself. A length validation bug in CIP handling drops ControlLogix, CompactLogix and GuardLogix controllers into a major nonrecoverable fault, and clearing it needs a person at the cabinet.
The Watch · Security desk

security
Mitsubishi's CNC advisory now lists 18 models exposed on TCP port 6831 distinct publisher
security
A low-privilege login reaches code execution on Rockwell's FactoryTalk Historian ME1 distinct publisher
security
CISA revises the Mitsubishi FA advisory a fourth time for one UDP denial-of-service bug1 distinct publisher
security
ASE2000's IEC 104 client accepts a forged peer certificate through version 2.371 distinct publisher
Compiled by The WatchSomething wrong?How this is made
CWE-119 sitting on top of a length field describes a familiar mechanism: the controller reads a declared length out of a CIP message and operates outside the bounds of the buffer holding it [1][3]. CISA published the advisory as ICSA-26-244-03 [18]. What the published text does not give you is a CVSS vector or a statement of what access the sender needs, so the only precondition you can establish from the document is the ability to put CIP traffic in front of the controller [12].
The recovery language is the part that changes the ticket's owner. A major nonrecoverable fault latches, and the advisory's own remediation text says a power cycle is what clears it [2]. Clearing the fault means someone walking to the panel; no remote action from an engineering workstation restores the controller.
Rockwell's fixed firmware sits exactly one patch release above the top of each affected band: 34.014 goes to 34.015, 35.013 to 35.014, 36.012 to 36.013 [15]. Three live trains got a targeted fix. The V33-and-earlier band got nothing in-train, so the only listed path for those controllers is a move up to V34.015 or later [16]. Sixteen product-and-version rows resolve to a single CVE across all four families, which reads as one shared code path rather than four separate bugs [14][4].
Short of firmware, the offered mitigation is Rockwell's security best practices plus the standard placement guidance CISA attaches to every ICS advisory: keep control systems off the internet, put them behind firewalls, isolate them from business networks, use a VPN when remote access is required [8][11]. None of that is specific to this bug. The work it implies is an inventory keyed on controller firmware revision, because a version band is the only thing here that distinguishes a vulnerable asset from a fixed one [5].
Rockwell found and self-reported the flaw, and the advisory reports no exploitation [13][9]. That ordering matters for planning: the fix exists before any public technique does, and the estates that have to buy an outage window to apply it are the ones with the most to gain from spending that window now rather than under a fault.
Ranked by verification strength, evidence, and original report placement.
A denial-of-service vulnerability exists in the affected Rockwell Automation Logix platforms due to improper validation of input length during CIP message processing.
Exploitation can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover.
The relevant weakness is CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer.
The affected product families are ControlLogix 5580, CompactLogix 5380, GuardLogix 5580 and Compact GuardLogix 5380.
For each affected family the listed versions are V33 and earlier, V34.011-V34.014, V35.011-V35.013 and V36.011-V36.012.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary document, no second reader
The version bands are precise to the patch digit and the fix targets line up with them arithmetically, which is the kind of detail an asset owner can check against a controller's firmware page this afternoon. The weakness is provenance breadth rather than depth: one advisory, sourced from the vendor, with no outside reproduction and no severity vector to argue with.
Fix shipped, uptake unknown
'Worldwide' is the whole of the deployment picture. Nothing tells us how many 5580s and 5380s are running affected firmware, how many sites have already spent an outage window getting to 34.015, or how many expose a CIP path to anything beyond the plant network. Firmware existing and firmware running are different facts, and only the first one is on the record.
Filed dry, felt physically
If anything the paperwork undersells this. 'Denial of service' reads like a reloaded page; here it is a major nonrecoverable fault on controllers running machinery, safety variants included, cleared only by a human cycling power. CISA gives that consequence one clause and grades the severity nowhere, so our headline sits ahead of the source in emphasis rather than behind it.
Vendor-found, vendor-framed
Rockwell reported the bug in its own firmware, which is creditable and also means the company set the scope. 'Denial of service' and the empty severity section are both vendor-shaped choices, relayed by CISA without an independent score; no researcher stands beside the write-up to push back on either.
The what is firm, the how-bad is blank
Product families, version bands, fix targets, CVE and advisory numbers are all nailed down and mutually consistent. What an operator needs next — whether exploitation takes credentials or just CIP reach, and how this ranks against the other outages competing for the same maintenance window — the document simply does not say.