Logix Platform DoS Hits ControlLogix, CompactLogix, GuardLogix
No mitigation exists short of a firmware upgrade, if the controller is reachable on the network, the clock starts when the advisory publishes.
TL;DR
CISA released an advisory for CVE-2026-9637, an uncontrolled resource consumption vulnerability in Rockwell Automation's Logix platform (ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380) affecting versions through V36.x. The flaw is exploitable remotely with low attack complexity (CVSS 7.5 under v3.1, 8.7 under v4.0) and produces a denial-of-service condition requiring a power cycle to recover. Remediation is a firmware upgrade to V37.011 or patched versions V34.015, V35.014, and V36.013. No public exploitation has been reported to CISA.
Rockwell Automation's Logix platform is the programmable logic controller family that runs discrete manufacturing and a substantial share of the defense industrial base. CVE-2026-9637 affects the full current line (ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380) across every firmware version through V36.x. The vulnerability sits in CIP message processing: improper input-length validation causes a memory leak that produces a major nonrecoverable fault. Recovery requires a power cycle and a controller download.
That's a hard operational impact. The controller doesn't degrade gracefully; it drops. For a production line or a defense contractor test cell, the downtime is whatever it takes to get someone to the cabinet and reload the program. Network segmentation reduces exposure but doesn't eliminate it, an attacker already on the OT network can trigger the fault with a crafted CIP message.
Rockwell's fix is a firmware upgrade. The primary path is V37.011; patched versions are also available for V34.015, V35.014, and V36.013. There is no configuration workaround, no firewall rule that substitutes for the update. Organizations that can't apply the firmware immediately are directed to Rockwell's general security best practices, which is the standard advisory language and not a substitute for patching.
This is the latest in a recurring pattern for Logix. CISA has published at least five prior advisories for the platform since 2022, CVE-2022-1161 (CVSS 10.0, remote code execution via untrusted control sphere), CVE-2022-3752 (DoS via crafted Ethernet/IP messages), CVE-2024-3493 (MNRF via malformed fragmented packets), CVE-2024-6242 (CIP command execution bypassing Trusted Slot), and CVE-2024-8626 (another memory-leak DoS with the same recovery profile). In each case, the vulnerability was remotely exploitable, low complexity, and required a firmware upgrade to close.
No public exploit code is known and CISA reports no active exploitation at this time. But the advisory has published. The vulnerability is described. For contractors subject to DFARS 252.204-7012 and NIST SP 800-171 control 3.11.1, the remediation clock starts now.
Published ·Deep Fathom