PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9140 Rockwell Automation CVE debrief

A denial-of-service security issue exists in the Rockwell Automation 1719-AENTR, caused by improper handling of a UDP unicast network storm, leading to device overload and loss of communication. This issue affects Industrial control system administrators and security teams responsible for Rockwell Automation 1718-AENTR/1719-AENTR devices. A power cycle is required to recover. The issue has a CVSS score of 7.5 and is classified as HIGH severity. Evidence is based on official CVE and source item records. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Vendor
Rockwell Automation
Product
1718/ 1719 Ex I/O
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-21
Advisory published
2026-07-21
Advisory updated
2026-07-21

Who should care

Industrial control system administrators and security teams responsible for Rockwell Automation 1718-AENTR/1719-AENTR devices should review and apply recommended security updates to prevent potential denial-of-service attacks.

Technical summary

The Rockwell Automation 1719-AENTR is vulnerable to a denial-of-service security issue due to improper handling of UDP unicast network storms. This causes the device to become overloaded and lose communication, requiring a power cycle to recover. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Industrial control system administrators and security teams should review and apply recommended security updates to prevent potential denial-of-service attacks. The issue is caused by improper handling of a UDP unicast network storm.

Defensive priority

Immediately review and apply vendor-recommended security updates to prevent potential denial-of-service attacks.

Recommended defensive actions

  • Apply Rockwell Automation's recommended security updates to version 3.012 or later.
  • Implement Rockwell Automation's security best practices.
  • Monitor for unusual network activity and system behavior.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the denial-of-service security issue in Rockwell Automation 1718-AENTR/1719-AENTR. Evidence is based on official CVE and source item records. The issue is caused by improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9140 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9140

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9140 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9140

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.