SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-9621

CRITICAL · CVSS 9.2 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

RSLinx® Classic is vulnerable to a denial-of-service attack due to improper handling of malformed CIP packets, which can lead to service crashes that necessitate a restart for recovery. This critical vulnerability, with a CVSS score of 9.2, poses significant risks to operational continuity and should be prioritized by organizations using RSLinx® Classic in their industrial control systems. Immediate attention is recommended to mitigate potential disruptions in service.

CVE
CVE-2026-9621
Severity
CRITICAL
CVSS
9.2
EPSS
0.31%

Original NVD Description

A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover