PatchSiren cyber security CVE debrief
CVE-2026-9140 Rockwell Automation CVE debrief
A denial-of-service security issue exists in the Rockwell Automation 1719-AENTR, caused by improper handling of a UDP unicast network storm, leading to device overload and loss of communication. This issue affects Industrial control system administrators and security teams responsible for Rockwell Automation 1718-AENTR/1719-AENTR devices. A power cycle is required to recover. The issue has a CVSS score of 7.5 and is classified as HIGH severity. Evidence is based on official CVE and source item records. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
- Vendor
- Rockwell Automation
- Product
- 1718/ 1719 Ex I/O
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-21
Who should care
Industrial control system administrators and security teams responsible for Rockwell Automation 1718-AENTR/1719-AENTR devices should review and apply recommended security updates to prevent potential denial-of-service attacks.
Technical summary
The Rockwell Automation 1719-AENTR is vulnerable to a denial-of-service security issue due to improper handling of UDP unicast network storms. This causes the device to become overloaded and lose communication, requiring a power cycle to recover. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Industrial control system administrators and security teams should review and apply recommended security updates to prevent potential denial-of-service attacks. The issue is caused by improper handling of a UDP unicast network storm.
Defensive priority
Immediately review and apply vendor-recommended security updates to prevent potential denial-of-service attacks.
Recommended defensive actions
- Apply Rockwell Automation's recommended security updates to version 3.012 or later.
- Implement Rockwell Automation's security best practices.
- Monitor for unusual network activity and system behavior.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the denial-of-service security issue in Rockwell Automation 1718-AENTR/1719-AENTR. Evidence is based on official CVE and source item records. The issue is caused by improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Official resources
-
CVE-2026-9140 CVE record
CVE.org
-
CVE-2026-9140 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T06:00:00.000Z and has not been modified since then.