CVE-2026-9625: RSLinx Classic® - Multiple Vulnerabilities
Published Sep 1, 2026
·Updated
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
Affected Software
1 affected component
Rockwell Automation RSLinx Classic
Event History
Sep 1, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionWeakness
Frequently Asked Questions
1
What must an attacker send to trigger the service crash?
The attacker must send a crafted CIP packet containing an oversized embedded message request to the RSLinx Classic service.
2
What is the operational impact if exploitation succeeds?
The RSLinx Classic service can crash, causing a denial of service. Recovery requires restarting the affected service.