CISA flags Rockwell 1756-EN2, EN3, ENBT DoS flaw
The uncomfortable part is not the CVSS score; it is the discontinued ENBT sitting in plants with no vendor fix.
TL;DR
CISA published ICSA-26-197-02 for CVE-2026-9653, a network-accessible denial-of-service flaw in Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT modules. EN2 and EN3 operators should update to V12.002 or segment control networks; ENBT V6.006 is discontinued and has no fix. CISA says no known public exploitation has been reported.
CVE-2026-9653 is a routine industrial control system advisory with one non-routine operational problem. Rockwell Automation has fixes for 1756-EN2 and 1756-EN3 modules at V12.002, but the affected 1756-ENBT V6.006 is discontinued and has no available fix. For defense-industrial-base contractors, municipal operators, and other critical manufacturing environments still running those modules, the Monday work is inventory, patch where possible, and isolate the control network where replacement or firmware work is not immediate.
The vulnerability is an improper validation issue in CIP Implicit Connection packets. CISA rates it CVSS v3.1 7.5, high, and says an unauthenticated attacker on the network could send crafted packets that continuously disrupt device connections, though connections recover immediately afterward. That is availability pain, not remote code execution, but in operational technology the distinction only comforts people who do not own the downtime.
CISA's mitigation guidance is the standard ICS set: minimize exposure, keep control devices off the internet, put control networks behind firewalls, isolate them from business networks, and keep VPN access current. The open question is procurement, not prose. CISA gives no general-availability timeline beyond Rockwell's V12.002 recommendation for EN2 and EN3, and ENBT owners are left with segmentation, replacement planning, and whatever end-of-life guidance Rockwell provides outside the advisory.
Published ·Deep Fathom