CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3576

As cited

Copy frozen at (site build).

vulnerabilities

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

Rockwell Automation released a security advisory for CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, and 1756-EN4TR communications modules affected by improper certificate revocation handling (CVE-2026-9636). The vulnerability allows network-based attackers to bypass CIP Security protections by establishing connections with revoked certificates. Affected versions range from V36 to V37 for controllers and V6.001 to V7.001 for the EN4TR module, with fixes available in V38.011 and V8.001 respectively.

Why it matters: Manufacturing facilities and critical infrastructure operators running these Rockwell Automation controllers need to prioritize patching to prevent unauthorized access to industrial control systems via certificate spoofing.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

Rockwell Automation released a security advisory for CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, and 1756-EN4TR communications modules affected by improper certificate revocation handling (CVE-2026-9636). The vulnerability allows network-based attackers to bypass CIP Security protections by establishing connections with revoked certificates. Affected versions range from V36 to V37 for controllers and V6.001 to V7.001 for the EN4TR module, with fixes available in V38.011 and V8.001 respectively.

Why it matters: Manufacturing facilities and critical infrastructure operators running these Rockwell Automation controllers need to prioritize patching to prevent unauthorized access to industrial control systems via certificate spoofing.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary