← Back to Feed

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

CVE-2017-16740

August 6, 2026 · The Hacker News · Severity: HIGH

A recent Forescout report revealed over 4,400 Rockwell Automation programmable logic controllers (PLCs) exposed online globally, including 2,844 in the U.S. and 22 in cities targeted by recent cyberattacks on water utilities. Nineteen of these exposed controllers were connected via the same mobile carrier network and ran firmware vulnerable to CVE-2017-16740, a critical Modbus TCP buffer overflow flaw (CVSS 8.6) affecting Rockwell’s MicroLogix 1400 Series B and C. While no confirmed compromises were found, attackers could exploit weak configurations—such as default passwords or public internet exposure—to disrupt operations, as seen in incidents across at least seven states since late July. The FBI and EPA issued advisories urging utilities to secure PLCs by removing them from public internet access, enforcing strong authentication, and isolating remote connections via VPNs or private networks. Over 70% of exposed U.S. controllers were on major carrier networks like Verizon, AT&T, and T-Mobile. Rockwell provided recovery guidance (Advisory SD1790) for devices locked by attackers, but firmware updates alone don’t mitigate risks from direct internet exposure. The incidents highlight systemic vulnerabilities in critical infrastructure, where shared network setups could enable attackers to replicate compromises across multiple targets. Proactive measures like network segmentation and logging are critical to prevent further disruptions.

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed controllers, not water utilities or confirmed victims. Forescout said the publicly described effects could be achieved without a vulnerability exploit: attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment. Neither the government alerts nor Forescout's analysis explains how the attackers found, selected, or initially accessed their targets.

Key Takeaways

  • Over 4,400 Rockwell Automation PLCs remain exposed online, with 22 found in water and wastewater systems, posing critical infrastructure risks.
  • The exposure stems from CVE-2017-16740, a decades-old vulnerability allowing unauthenticated remote access to programmable logic controllers.
  • Rockwell has published advisories PN1010 and SD1790 urging organizations to isolate industrial control systems from the internet.
☕ Buy a Coffee