SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-9653

HIGH · CVSS 8.7 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The vulnerability affects the 1756-EN2, EN3, and ENBT communication modules, allowing an attacker on the network to send specially crafted CIP Implicit Connection packets that can cause a denial-of-service condition by disrupting device connections. Although the connections recover immediately after the attack, the potential for disruption could impact network reliability and operational continuity. Organizations utilizing these communication modules should prioritize addressing this issue to safeguard against potential network interruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-9653
Severity
HIGH
CVSS
8.7
EPSS
0.18%

Original NVD Description

A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.