← Back to Feed

Rockwell Automation ArmorStart LT

CVE-2026-19471CVE-2026-19472

September 3, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT <=v2.001 (CVE-2026-19471, CVE-2026-19472) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ArmorStart LT Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-19471 Multiple stored cross-site scripting security issues exist within ArmorStart LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page. View CVE Details Affected Products Rockwell Automation ArmorStart LT Vendor:Rockwell Automation Product Version:Rockwell Automation ArmorStart LT: <=v2.001 Product Status:known_affected Remediations MitigationRockwell Automation has corrected this issue in firmware version v2.002, and encourages all users to update to the newest version. MitigationUsers of the affected software who are not able to upgrade to one of the corrected versions should follow Rockwell Automation's security best practices.https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight MitigationFor more information on this issue, see the Rockwell Automation security advisory at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.htmlhttps://www.rockwellautomation.com/en-us/trust-center/security-advisories.html Relevant CWE: CWE-79 Improper...

Key Takeaways

  • CISA published an advisory for Rockwell Automation ArmorStart LT urging users to apply vendor patches and mitigations.
  • Organizations using Rockwell Automation ArmorStart LT should review CISA's advisory and apply security updates promptly.
  • Active exploitation of vulnerabilities in Rockwell Automation ArmorStart LT has been reported, making patching urgent for affected organizations.
☕ Buy a Coffee