CISA flags Rockwell 1718/1719 Ex I/O DoS flaw
For plants running version 3.011, the practical work is narrow: schedule firmware 3.012 before a network storm becomes downtime.
TL;DR
CISA published ICSA-26-202-08 for CVE-2026-9140, a Rockwell Automation 1718-AENTR/1719-AENTR Ex I/O denial-of-service flaw affecting version 3.011. Rockwell recommends upgrading to version 3.012 or later. Critical manufacturing operators, including defense-industrial-base primes and subs with these devices, should treat this as a remote, low-complexity availability issue. CISA says it has no reports of known public exploitation.
CISA’s advisory is a straight patch item. CVE-2026-9140 affects Rockwell Automation 1718-AENTR/1719-AENTR Ex I/O version 3.011 and carries CVSS 3.1 7.5 and CVSS 4.0 8.7 scores. The failure mode is availability, not data theft: improper handling of a UDP unicast network storm can overload the device, cause loss of communication and require a power cycle to recover.
Rockwell’s fix is firmware version 3.012 or later. For critical manufacturing sites and defense-industrial-base suppliers using these modules, the Monday work is asset confirmation, outage planning and segmentation review. CISA repeats the usual ICS guidance: keep control system devices off the public internet, isolate control networks from business networks, use updated VPNs when remote access is required and report suspected malicious activity through established channels.
Published ·Deep Fathom