As cited
Copy frozen at (site build).
vulnerabilities
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
Rockwell Automation released a security advisory for CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, and 1756-EN4TR communications modules affected by improper certificate revocation handling (CVE-2026-9636). The vulnerability allows network-based attackers to bypass CIP Security protections by establishing connections with revoked certificates. Affected versions range from V36 to V37 for controllers and V6.001 to V7.001 for the EN4TR module, with fixes available in V38.011 and V8.001 respectively.
Why it matters: Manufacturing facilities and critical infrastructure operators running these Rockwell Automation controllers need to prioritize patching to prevent unauthorized access to industrial control systems via certificate spoofing.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
Rockwell Automation released a security advisory for CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, and 1756-EN4TR communications modules affected by improper certificate revocation handling (CVE-2026-9636). The vulnerability allows network-based attackers to bypass CIP Security protections by establishing connections with revoked certificates. Affected versions range from V36 to V37 for controllers and V6.001 to V7.001 for the EN4TR module, with fixes available in V38.011 and V8.001 respectively.
Why it matters: Manufacturing facilities and critical infrastructure operators running these Rockwell Automation controllers need to prioritize patching to prevent unauthorized access to industrial control systems via certificate spoofing.
- Source published
- First seen by Cybersecurity Tracker