Security1 distinct publisher2 min readPublished
The four CVEs share one patch target and one recovery step, a manual service restart, but CISA's advisory carries no CVSS metrics and no per-CVE mapping, so the only axis an OT team can rank them on is network reachability.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The bug family is stated in the advisory's own labels. One description is tagged CWE-190, integer overflow or wraparound; two are tagged CWE-191, integer underflow [7] [8]. Three of four descriptions in the same class puts the fault in length arithmetic on CIP fields, and the fourth, the oversized embedded message request, reads as the same failure in plainer words [6] [12]. The published text carries no CWE for that fourth item [12].
The advisory's gaps continue from there. Each Metrics heading in the text is empty of a score or a vector [15]. The four CVE numbers appear once, against the version range, and the four crash descriptions that follow are not labelled with CVEs, so nobody outside Rockwell can say which number is the Forward Close bug [13]. The advisory is silent on exploitation status and on whether the sender needs credentials or local adjacency [16].
The advisory confines the stated impact to denial of service, stopping short of any claim of code execution or altered controller state [1]. That sets the ceiling, and it splits the honest read two ways. A host that accepts CIP only from a segment you control, with someone on shift who can restart a Windows service, has a maintenance-window item [3]. A host that answers CIP from a plant network carrying vendor laptops, or from anything routed, has a repeatable link outage that lasts as long as the sender keeps sending [3]. Whatever window 4.60 needs, an attacker in the second case takes it unscheduled [9]. Rockwell's fallback for hosts that cannot take the upgrade is a general security best-practices document rather than a per-CVE workaround, so there is nothing narrow to deploy in front of a service you have to leave unpatched [10]. Which case you are in is answered by your network diagram, not by the advisory.
Ranked by verification strength, evidence, and original report placement.
CISA's advisory states that successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product.
The affected versions are Rockwell Automation RSLinx Classic 4.50 and earlier, covering CVE-2026-9621, CVE-2026-9622, CVE-2026-9624 and CVE-2026-9625.
A crafted CIP packet can cause the RSLinx Classic service to crash, requiring a restart of the service to recover; the advisory attributes the issue to improper handling of a malformed packet.
One of the described issues involves a crafted CIP packet targeting the Forward Close service, which causes the RSLinx Classic service to crash.
One of the described issues causes the RSLinx Classic service to crash due to insufficient data length validation.
One of the described issues involves a crafted CIP packet with an oversized embedded message request, which causes the RSLinx Classic service to crash.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
security
One malformed CIP message faults a Logix controller until someone power-cycles it1 distinct publisher
security
Rockwell's redundancy config tool loads a standard user's DLL as SYSTEM1 distinct publisher
security
A weak bcrypt setting turns every unencrypted OTTO Fleet Manager backup into a credential file1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One document, checkable line by line
Every fact in this story can be pointed at a specific line of CISA's advisory — versions, CWE tags, the 4.60 fix, the empty Metrics headings — which is why the descriptive claims hold up. What it cannot do is corroborate: the crash behaviour is Rockwell's own account of Rockwell's own product, relayed by CISA, with no researcher, no proof-of-concept and no independent reproduction. Our own close reading also mis-scored one entry as unlabelled when CWE-120 sits right there, a reminder that a lone source rewards careful quoting over inference.
Patch shipped, field uptake unmeasured
The remediation exists and is singular — 4.60 — and CISA describes the product as deployed worldwide in critical manufacturing. That is the ceiling of what we know. Nobody counts installed 4.50 seats, nobody reports an upgrade rate, and no exploitation is claimed, so the gap between 'a fix is available' and 'plants are running it' is entirely unlit. In OT fleets where an upgrade waits for a maintenance window, that gap is usually the whole story.
Slightly harder on the advisory than the text warrants
Our framing is deliberately unexcited — denial of service, one upgrade, no known exploitation — and on the central point it is right: without CVSS or per-CVE mapping, reachability really is the only axis an OT team can sort these four on. The overshoot is narrower than the headline. Calling the fourth description unlabelled made the advisory look barer than it is, since CWE-120 is printed there; the weakness picture is not uniformly integer wraparound.
Vendor-found, vendor-worded, fix already in hand
Rockwell reported these flaws to CISA itself, and the disclosure arrives with the patch already published and the fallback pointing back to Rockwell's own support portal. That is responsible sequencing, and it is also the arrangement in which a vendor has the most control over tone: crash-and-restart language, no severity numbers to be compared against last quarter's advisories, no outside researcher with a blog post. Nothing here suggests bad faith; it does mean the only voice describing the bugs is the one that benefits from them reading as routine.
Confident about the text, thin on the world
Treat the version numbers, the CWE tags and the 4.60 fix as reliable — they are quotations. Treat everything about consequence as open: how easily the packet reaches a real RSLinx host, which CVE does what, how bad any single one is, and whether anyone has tried. A second account, a CVSS vector, or one integrator saying what a service restart costs on their line would each move this materially.