Executive Summary
Four critical denial-of-service vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) were discovered in Rockwell Automation's RSLinx Classic versions 4.50 and earlier. These vulnerabilities allow attackers to crash the RSLinx Classic service by sending specially crafted CIP packets, exploiting integer overflow, integer underflow, and buffer overflow conditions. The vulnerabilities affect critical manufacturing infrastructure worldwide and require service restarts to recover, potentially disrupting industrial operations and production systems.
These vulnerabilities highlight the growing threat landscape facing industrial control systems as cybercriminals increasingly target critical infrastructure. With the rise of nation-state actors and ransomware groups focusing on OT environments, securing industrial communication protocols like CIP has become paramount for operational resilience.
Why This Matters Now
Industrial control systems are facing unprecedented cyber threats as attackers shift focus to critical infrastructure. These RSLinx Classic vulnerabilities demonstrate how easily OT networks can be disrupted, making immediate patching and network segmentation critical for manufacturing continuity.
Attack Path Analysis
Attackers exploit denial-of-service vulnerabilities in Rockwell Automation RSLinx Classic through crafted CIP packets targeting industrial control systems. The attack progresses from network-accessible ICS components to service disruption, potentially enabling broader industrial network compromise and operational impact through service unavailability and system manipulation.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers send malformed CIP packets to network-accessible RSLinx Classic services exploiting buffer overflow and integer overflow vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625)
Related CVEs
CVE-2026-9621
CVSS 9.2Integer overflow vulnerability in Rockwell Automation RSLinx Classic allows remote attackers to cause denial-of-service through malformed CIP packets
Affected Products:
Rockwell Automation RSLinx Classic – <= 4.50
Exploit Status:
no public exploitCVE-2026-9622
CVSS 8.7Integer underflow vulnerability in Rockwell Automation RSLinx Classic allows remote attackers to crash service via crafted CIP packets targeting Forward Close service
Affected Products:
Rockwell Automation RSLinx Classic – <= 4.50
Exploit Status:
no public exploitCVE-2026-9624
CVSS 8.7Integer underflow vulnerability in Rockwell Automation RSLinx Classic due to insufficient data length validation allows denial-of-service via crafted CIP packets
Affected Products:
Rockwell Automation RSLinx Classic – <= 4.50
Exploit Status:
no public exploitCVE-2026-9625
CVSS 8.7Buffer overflow vulnerability in Rockwell Automation RSLinx Classic allows remote attackers to crash service through oversized embedded message requests in CIP packets
Affected Products:
Rockwell Automation RSLinx Classic – <= 4.50
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Client Execution
Endpoint Denial of Service
Application or System Exploitation
Exploitation of Remote Services
Active Scanning
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
CISA Zero Trust Maturity Model 2.0 – Microsegmentation and Protocol Inspection
Control ID: Network Segmentation - Advanced
NIS2 Directive – Risk Management Measures for Network and Information Systems
Control ID: Article 21.2(a)
DORA – Testing of ICT Business Continuity Policy
Control ID: Article 11
PCI DSS 4.0 – Software Engineering Techniques for Secure Development
Control ID: 6.2.4
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Critical RSLinx Classic vulnerabilities enable denial-of-service attacks on manufacturing control systems, disrupting production operations and requiring immediate patching or network segmentation.
Automotive
Manufacturing execution systems using RSLinx Classic face operational disruption from crafted CIP packets, potentially halting assembly lines and compromising just-in-time production schedules.
Oil/Energy/Solar/Greentech
Energy infrastructure relies on RSLinx Classic for SCADA communications; buffer overflow vulnerabilities could cause service outages affecting power generation and distribution systems.
Utilities
Water treatment and power grid operations using RSLinx Classic are vulnerable to service crashes from malformed packets, requiring enhanced network monitoring and access controls.
Sources
- Rockwell Automation RSLinx Classichttps://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01Verified
- Rockwell Automation Security Advisorieshttps://www.rockwellautomation.com/en-us/trust-center/security-advisories.htmlVerified
- Rockwell Automation Security Best Practiceshttps://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_USVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the attack's blast radius by constraining lateral movement through industrial network segments and limiting attacker reach to critical manufacturing systems beyond the initial RSLinx Classic compromise.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely limit the attacker's ability to reach RSLinx Classic services across multiple industrial network zones, reducing the scope of vulnerable endpoints accessible for CIP packet exploitation
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely constrain the attacker's ability to leverage RSLinx Classic access for broader privilege escalation across industrial device networks, limiting elevated access scope to segmented zones
Control: East-West Traffic Security
Mitigation: Traffic inspection and segmentation controls would likely limit the attacker's ability to pivot between industrial network segments, constraining access to PLCs and HMI systems through enforced communication policies
Control: Multicloud Visibility & Control
Mitigation: Network visibility and monitoring capabilities would likely detect and constrain unauthorized industrial protocol communications, limiting the attacker's ability to maintain persistent command channels across network segments
Control: Egress Security & Policy Enforcement
Mitigation: Egress filtering and policy controls would likely constrain the attacker's ability to extract industrial data and process configurations, limiting outbound data flows from compromised industrial network segments
While RSLinx Classic service disruption may still occur within affected segments, the operational impact would likely be constrained to isolated network zones rather than cascading across the entire manufacturing environment
Impact at a Glance
Affected Business Functions
- Industrial Process Control
- Manufacturing Operations
- SCADA Systems
- Device Communication Management
Estimated downtime: 1 days
Estimated loss: N/A
No data exposure identified. Vulnerabilities result in denial-of-service conditions affecting RSLinx Classic service availability but do not compromise data confidentiality or integrity.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate industrial control systems from broader network access and prevent lateral movement between ICS components
- • Deploy Inline IPS (Suricata) to detect and block malformed CIP packets and exploit attempts targeting industrial protocols before they reach critical systems
- • Enable Multicloud Visibility & Control to monitor anomalous interactions and repeated malformed requests against industrial communication services
- • Establish East-West Traffic Security controls to prevent unauthorized lateral movement between industrial network segments and operational technology assets
- • Configure Egress Security & Policy Enforcement to detect unauthorized data exfiltration from industrial systems and block communications to unauthorized external destinations



