Source context: this article examines information published by the source on September 01, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What the vulnerability is
Rockwell Automation RSLinx Classic is affected by four distinct vulnerabilities that can lead to a denial-of-service (DoS) condition. These flaws allow an attacker to send specially crafted Common Industrial Protocol (CIP) packets to the target system, causing the RSLinx Classic service to crash. Recovery from such an event requires a manual restart of the service.
The technical root causes vary across the identified CVEs:
* CVE-2026-9621: Improper handling of malformed packets (CWE-190: Integer Overflow or Wraparound).
* CVE-2026-9622: A flaw targeting the Forward Close service (CWE-191: Integer Underflow).
* CVE-2026-9624: Insufficient data length validation (CWE-191: Integer Underflow).
* CVE-2026-9625: Processing of oversized embedded message requests (CWE-120: Classic Buffer Overflow).
Exposure and applicability
These vulnerabilities apply to all installations of RSLinx Classic version 4.50 and earlier. The attack vector is network-based, meaning any system capable of sending CIP packets to the affected service is a potential source of exploitation.
Infrastructure owners in critical manufacturing sectors are most likely to be impacted, as this software is used for industrial communications. Because these vulnerabilities do not require authentication or user interaction, any exposed RSLinx Classic instance on a reachable network is at risk of service disruption.
Remediation priorities
Our analysis suggests the following prioritization for vulnerability management teams:
- Immediate Update: The primary corrective action is updating RSLinx Classic to version 4.60, which contains the vendor’s fixes for all four CVEs.
- Network Segmentation: For systems where immediate patching is not feasible due to operational constraints, defenders should isolate the control system network from business networks and the internet using firewalls.
- Secure Remote Access: If remote access to the affected environment is required, it should be restricted to secure methods such as Virtual Private Networks (VPNs), ensuring the VPN itself is fully patched.
How to validate remediation
To verify that exposure has been reduced, defenders should move beyond simple version checks:
* Version Verification: Confirm the installed version is 4.60 or later via the software’s properties or system registry.
* Network Validation: Use firewall logs or network scanning tools to verify that CIP traffic is restricted to authorized engineering workstations and cannot originate from untrusted zones.
* Operational Stability: Monitor service uptime and crash logs for RSLinx Classic to ensure no unexpected restarts are occurring, which could indicate attempted exploitation or instability.
Limits and open questions
Updating to version 4.60 addresses the specific integer overflows, underflows, and buffer copies identified in these CVEs; however, it does not guarantee immunity from all possible DoS attacks targeting the CIP protocol.
There is currently no reported evidence of public exploitation for these vulnerabilities. A residual risk remains for organizations that cannot patch immediately: while network isolation reduces the likelihood of initial access, it does not remove the underlying vulnerability from the host. If an attacker gains a foothold within the trusted control network, the service remains susceptible until the update is applied.
Source and editorial note
Rockwell Automation RSLinx Classic · Source date: September 01, 2026 · Retrieved September 01, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗