# CVE-2026-9637

## Summary

- **CVE ID:** CVE-2026-9637
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-119
- **Published:** Sep 1, 2026
- **Last Modified:** Sep 1, 2026

## Description

A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover

## Affected Products

- Rockwell Automation — CompactLogix® 5380 / ControlLogix® 5580 (V33 and prior, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012)

## References

- [CNA](https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1792.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.31%
- **EPSS Percentile:** 23.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._