CVE-2026-19472: Rockwell Automation ArmorStart® LT Denial Of Service
Published Sep 1, 2026
·Updated
A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability
Affected Software
1 affected component
ArmorStart LT
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation ArmorStart® LTto a version that resolves this vulnerability.Fixed in v2.002
Event History
Sep 1, 2026
CVE Published
via MITRE·12:51 PM
Data Sourced
via MITRE·12:51 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to do to trigger the denial of service?
The issue is triggered by sending a crafted HTTP PUT request to the ArmorStart LT embedded web server.
2
Which service is affected when the issue is exploited?
Successful exploitation can cause a loss of availability for the embedded web server. The provided information does not state that other ArmorStart LT functions are affected.