CVE-2026-9624: RSLinx Classic® - Multiple Vulnerabilities
Published Sep 1, 2026
·Updated
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.
Affected Software
1 affected component
Rockwell Automation RSLinx Classic
Event History
Sep 1, 2026
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What must an attacker send to trigger the issue?
An attacker must send a crafted CIP packet that exploits insufficient data-length validation in the RSLinx Classic service.
2
What is required to restore operation after exploitation?
The RSLinx Classic service must be restarted after it crashes.