Executive Summary
In July 2026, Rockwell Automation disclosed a security vulnerability (CVE-2026-9636) affecting its CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR communication modules. The flaw involves improper handling of Certificate Revocation Lists (CRLs), allowing attackers to use revoked certificates to establish unauthorized connections, potentially bypassing CIP Security protections. This vulnerability impacts firmware versions V36 to V37 for the affected products. (rockwellautomation.com)
The incident underscores the critical importance of robust certificate validation processes in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize timely firmware updates and adhere to security best practices to mitigate potential risks.
Why This Matters Now
The CVE-2026-9636 vulnerability highlights the ongoing challenges in securing industrial control systems against sophisticated cyber threats. With increasing reliance on connected devices in critical infrastructure, ensuring proper certificate validation is essential to prevent unauthorized access and maintain operational integrity.
Attack Path Analysis
An attacker exploits the certificate revocation flaw in Rockwell Automation's CompactLogix 5380 and ControlLogix 5580 controllers to establish unauthorized connections. By leveraging the vulnerability, the attacker gains unauthorized access to the controllers. The attacker moves laterally within the network to identify and access other vulnerable devices. A command and control channel is established to maintain persistent access and control over the compromised devices. Sensitive data is exfiltrated from the compromised controllers to an external server. The attacker disrupts industrial processes by sending malicious commands, leading to operational downtime.
Kill Chain Progression
Initial Compromise
Description
An attacker exploits the certificate revocation flaw in Rockwell Automation's CompactLogix 5380 and ControlLogix 5580 controllers to establish unauthorized connections.
Related CVEs
CVE-2026-9636
CVSS 5.9A security issue exists within CompactLogix 5380, ControlLogix 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The controller fails to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL), potentially allowing a network-based attacker to establish a connection using a certificate that should be untrusted, bypassing CIP Security protections.
Affected Products:
Rockwell Automation ControlLogix 5580 – V36, V37
Rockwell Automation CompactLogix 5380 – V36, V37
Rockwell Automation GuardLogix 5580 – V36, V37
Rockwell Automation Compact GuardLogix 5380 – V36, V37
Rockwell Automation 1756-EN4TR – V6.001, V7.001
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Steal or Forge Authentication Certificates
Install Root Certificate
Code Signing
SIP and Trust Provider Hijacking
Code Signing Policy Modification
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Cryptographic Key Establishment and Management
Control ID: SC-12
PCI DSS 4.0 – Key Management Processes and Procedures
Control ID: 3.6.5
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.14
DORA – ICT Risk Management Framework
Control ID: Article 6
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Critical vulnerability in Rockwell Automation ControlLogix systems allows certificate bypass, compromising CIP Security protections in manufacturing control environments.
Automotive
Manufacturing control systems vulnerability could enable unauthorized network access, disrupting production lines and quality control processes through certificate revocation failures.
Oil/Energy/Solar/Greentech
CompactLogix controller vulnerability poses denial-of-service risks to energy infrastructure, potentially bypassing security controls in critical operational technology networks.
Utilities
Certificate revocation handling flaw in industrial controllers threatens grid stability and service continuity through potential unauthorized system access and operations disruption.
Sources
- Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Modulehttps://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05Verified
- SD1788 | Security Advisory | Rockwell Automationhttps://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1788.htmlVerified
- NVD - CVE-2026-9636https://nvd.nist.gov/vuln/detail/CVE-2026-9636Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it enforces strict segmentation and controlled access, which would likely limit the attacker's ability to move laterally and exfiltrate data.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to establish unauthorized connections would likely be constrained, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be limited, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be restricted, reducing the risk of further system compromise.
Control: Multicloud Visibility & Control
Mitigation: The establishment of command and control channels would likely be detected and disrupted, reducing persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely be constrained, reducing data loss.
The attacker's ability to disrupt industrial processes would likely be limited, reducing operational downtime.
Impact at a Glance
Affected Business Functions
- Industrial Control Systems
- Manufacturing Operations
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts targeting known vulnerabilities.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual network activities.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Regularly update and patch all devices to mitigate known vulnerabilities and reduce the attack surface.



