CISA flags CVE-2026-12659 in Rockwell Flex 5000 Adapter
The practical risk is recovery: a successful attack means power-cycling the module and associated I/O after crafted Common Industrial Protocol traffic.
TL;DR
CISA issued ICSA-26-197-08 for Rockwell Automation Flex 5000 Adapter 6.011, where CVE-2026-12659 lets crafted Common Industrial Protocol (CIP) packets trigger a denial-of-service condition. Rockwell rates the double-free flaw CVSS 3.1 7.5 and recommends upgrading to 6.012; CISA reported no known public exploitation. Defense-industrial-base primes and suppliers running the adapter in critical manufacturing should plan the firmware move, because recovery requires a power cycle of the module and associated I/O.
For Monday, this is a firmware-and-exposure check. Inventory Flex 5000 Adapter 6.011, confirm whether it sits in production paths where a reset would interrupt operations, and schedule the Rockwell 6.012 upgrade if change control allows it. CISA’s advisory is straightforward on the exploit shape: crafted Common Industrial Protocol packets can trigger mishandling of exceptional conditions, causing denial of service, and restoring the module and associated I/O requires a power cycle. The double-free label is less common in this corner of industrial-control advisories, while the control answer is familiar: keep control-system devices off the internet, segment them from business networks, treat VPN access as another patchable dependency, and run the impact analysis before touching a live cell. The advisory does not state a 6.012 availability timeline or say whether the fix needs coordination across multi-module deployments, so operations still owns the outage math.
Published ·Deep Fathom