HomeUpdatesRockwell Automation: Patch for critical vulnerabilities in ICS controllers

Rockwell Automation: Patch for critical vulnerabilities in ICS controllers

Rockwell Automation has released critical security updates that address multiple vulnerabilities in key industrial products, including its Logix and CompactLogix controllers, Flex I/O adapters, RSLinx communications software, and FactoryTalk. The vulnerabilities, disclosed through a coordinated disclosure process, range in severity from high to critical and pose a threat to industrial environments worldwide. CISA re-issued the related notices on June 16, 2026, highlighting their importance to critical infrastructure and confirming that the issues are of sufficient severity.

Rockwell Automation

Rockwell Automation: Vulnerabilities in Software, Controllers, Flex I/O and RSLinx

FactoryTalk Historian Site Edition is one of the most concerning areas of the new update rollup. Rockwell Automation has patched three high- and critical-severity vulnerabilities that could allow for authentication bypass and denial-of-service (DoS). The software is a particularly vulnerable target for attackers seeking broader network access. The recurring appearance of vulnerabilities in historian components — with FactoryTalk Historian SE 11 also mentioned in previous reports from 2026 — suggests that the category remains under sustained pressure from security researchers and malicious actors.

See also: Microsoft: Discloses critical vulnerabilities in Rockwell Automation PanelView Plus

FactoryTalk Analytics PavilionX is affected by CVE-2025-14272, a serious improper API authorization. The flaw allows an unauthorized user to perform privileged operations, such as user and role management, as well as other administrative actions. The existence of such a vulnerability in industrial data analytics can lead to serious business consequences, especially in environments where PavilionX is used for process optimization and real-time decision making.

In CompactLogix , ControlLogix , Compact GuardLogix and GuardLogix controllers, Rockwell Automation has fixed a high-severity DoS vulnerability that can cause a serious, non-recoverable fault, requiring a special recovery plan. The severity of a non-recoverable fault should not be underestimated: in production environments, a forced shutdown of a controller can mean hours or even days of lost production.

Some CompactLogix controllers are also affected by two additional DoS.

See also: Rockwell Automation tells administrators to disconnect ICS devices

Rockwell Automation: Patch for critical vulnerabilities in ICS controllers

Flex I/O dual-port Ethernet/IP adapters face two serious issues: a DoS flaw and a critical vulnerability that allows an unauthenticated attacker to password web interface , potentially leading to unauthorized access and account takeover.

In RSLinx Classic, Rockwell Automation has patched the legacy vulnerability CVE-2020-13573, a DoS issue introduced via a third-party component that affects versions 4.50 and earlier. The presence of this vulnerability in the 2026 advisory lists — six years after it was originally reported — demonstrates how long-term exposure can be in industrial software and how difficult it is to update legacy systems in operational environments.

It is worth noting that Rockwell recently confirmed the exploitation of an old vulnerability with the identifier CVE-2021-22681. However, the new announcements clarify that none of the newly fixed vulnerabilities have yet been exploited by malicious actors.

CISA republished most of Rockwell's announcements, but did not issue a separate announcement for the FactoryTalk Historian vulnerabilities , according to SecurityWeek. This highlights the importance of monitoring both manufacturer and federal agency announcements for a complete picture of the threat landscape .

See also: CISA: Hikvision and Rockwell Automation vulnerabilities in the KEV Catalog

Rockwell Automation: Patch for critical vulnerabilities in ICS controllers

Protection against security gaps

For organizations using Rockwell Automation products in industrial environments, immediate action is imperative. The first step is to apply available patches with priority to historian, controller, and communications components exposed to the factory network. At the same time, it is critical to fully inventory all Rockwell assets , including legacy RSLinx Classic and Logix/CompactLogix installations. Segmenting OT networks from corporate IT, restricting access to historian and controller management interfaces, prohibiting CIP protocol exposure to untrusted hosts, and monitoring for unusual traffic patterns are key mitigation measures.

Where immediate patching is not feasible due to operational constraints, the use of access control lists, jump hosts, allowlisting can significantly reduce risk. Finally, validating backups and recovery procedures is essential to reduce the operational impact in the event of DoS conditions.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS