Rockwell Automation recommends updating affected firmware to the following corrected versions: V37.011, 34.015, 35.014, or 36.013 depending on the current platform version. Customers unable to upgrade should minimize network exposure, isolate control system devices behind firewalls, and ensure they are not accessible from the internet. Use VPNs for remote access and perform impact analysis prior to deploying defensive measures.
Quick answers
What is CVE-2026-9637?
Rockwell Automation recommends updating affected firmware to the following corrected versions: V37.011, 34.015, 35.014, or 36.013 depending on the current platform version. Customers unable to upgrade should minimize network exposure, isolate control system devices behind firewalls, and ensure they are not accessible from the internet. Use VPNs for remote access and perform impact analysis prior to deploying defensive measures.
How severe is CVE-2026-9637?
high, CVSS 7.5
Is CVE-2026-9637 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-9637 be mitigated?
Rockwell Automation recommends updating affected firmware to the following corrected versions: V37.011, 34.015, 35.014, or 36.013 depending on the current platform version. Customers unable to upgrade should minimize network exposure, isolate control system devices behind firewalls, and ensure they are not accessible from the internet. Use VPNs for remote access and perform impact analysis prior to deploying defensive measures.
Rockwell Automation recommends updating affected firmware to the following corrected versions: V37.011, 34.015, 35.014, or 36.013 depending on the current platform version. Customers unable to upgrade should minimize network exposure, isolate control system devices behind firewalls, and ensure they are not accessible from the internet. Use VPNs for remote access and perform impact analysis prior to deploying defensive measures.
Rockwell Automation has disclosed a denial-of-service vulnerability (CVE-2026-9637) affecting the Logix Platform family. The flaw stems from improper validation of input length during CIP message processing and can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover. Four product lines are affected: ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380, across firmware versions up to and including V36.012. Rockwell Automation has released firmware updates (V37.011, 34.015, 35.014, 36.013) to address the issue. CISA and the vendor recommend isolating control system networks and minimizing internet exposure as defensive measures while patches are applied.